Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
Key takeaways
- Decloak’s free scan runs in ~15 seconds, needs no account, and checks both secret exposure and vulnerable third - party scripts.
- Layer 4 flags known vulnerable JavaScript libraries and dangerous patterns like
eval(). - Layer 7 identifies exposed service_role keys or other platform - specific secrets that ended up in client code.
- No installation required; just paste your SPA URL into the web UI.
How does Decloak detect exposed secrets in a SPA?
Decloak’s free scan examines every file that the browser can request, including inline scripts, external JavaScript bundles and HTML comments. It flags any high - entropy string that looks like an AWS, Google, Stripe or GitHub key, as well as JWTs and private - key blocks. The finding shows the exact location (file and line) but never stores the secret itself, proving the exposure without keeping a copy.
Steps
- Open the free Decloak scanner at
https://decloak.com/scan. - Paste the public URL of your single - page app and press Start Scan.
- Wait ~15 seconds for the report to appear.
- In the JavaScript CVE section (Layer 4) look for entries labeled Potential secret in JavaScript - each entry lists the file and a redacted snippet.
How does Decloak find vulnerable third - party scripts?
Layer 4 uses the Retire.js vulnerability database to match library names and versions found in every <script src> tag or bundled file. It also flags dangerous code patterns such as eval(), innerHTML sinks and wildcard postMessage targets. Layer 7 adds platform - specific checks; for example, if a Supabase service_role key appears in client - side code it will be reported as a publicly readable database credential.
Steps
- After the scan finishes, expand the JavaScript CVE section.
- Review entries that list a library name, version and CVE ID (e.g.,
jquery 3.4.0 - CVE - 2019 - 11358). - Check the dangerous pattern subsection for
eval()or missing Subresource Integrity (integrityattribute). - If the report shows a publicly readable Supabase table or exposed service_role key, treat it as a critical secret leak.
What does the free scan cover?
The free tier runs eight core layers:
- HTTP/TLS posture
- Static HTML analysis
- Rendered - page network behaviour
- JavaScript CVE scanning (vulnerable libraries, dangerous patterns, secret strings)
- Tag manager intelligence
- Third - party domain mapping
- Vibe - coded platform security (exposed platform secrets)
- AI - written executive summary All of these run without authentication and return a graded, shareable report in about 15 seconds.
When should I move beyond the free scan?
If you need deeper CI/CD integration, consider the paid tiers:
- Starter adds DNS/TLS deep analysis and subdomain takeover detection (Layer 9).
- Enterprise includes Active Security Testing (Layer 8) and AI - Pentesting, which actually attempts exploitation of findings such as vulnerable libraries. These layers provide confirmation that a vulnerability is exploitable, but the free scan already gives you a reliable snapshot of secret exposure and library risk.
Quick checklist for a pre - audit SPA review
| Item | Decloak layer | How to verify |
|---|---|---|
| Hard - coded API keys, JWTs, private - key blocks | Layer 4 (JavaScript CVE) | Look for Potential secret in JavaScript entries |
| Out - of - date third - party libraries | Layer 4 (JavaScript CVE) | Review library name, version and CVE list |
| Missing Subresource Integrity on external scripts | Layer 4 (dangerous pattern) | Check for Missing SRI warnings |
| Mixed - content HTTP resources on HTTPS page | Layer 3 (network behaviour) | Look for Mixed content entries |
| Platform - specific secrets (Supabase service_role, Bubble Data API) | Layer 7 (vibe - coded platform) | Review Publicly readable database or Exposed service_role findings |
How to act on the findings
- Remove or rotate any secret that appears in the report. Move it to a server - side environment variable and reference it via a backend endpoint.
- Upgrade vulnerable libraries to the latest patched version. If you cannot upgrade immediately, add Subresource Integrity with the correct hash and consider loading the library from a trusted CDN.
- Add
integrity=attributes to all external scripts and stylesheets. - Fix mixed content by updating all
http://URLs tohttps://or proxying them through a secure endpoint. - Enable platform security controls - for Supabase enable Row Level Security on every table and never ship the
service_rolekey to the client. - Re - run the free Decloak scan to confirm the issues are resolved before the formal audit.
Where to learn more
- Decloak’s free scan overview page explains the eight core layers and how the report is generated.
- The journal post AI Pentesting Explained: What It Is, Who It’s For and What Decloak Offers details how the Active Testing layer confirms exploitability.
- For compliance mapping, see Compliance Mapping Explained.
Running Decloak’s free scan gives you a fast, evidence - backed view of secret exposure and vulnerable scripts, letting you fix the most critical problems before an auditor walks through your code.
Related guides
How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation
Learn how to schedule Decloak scans via the REST API, compare results across runs, and push new or regressed findings to Jira or Linear automatically.
How can Decloak give auditor - ready proof for SOC 2 and ISO 27001 without weeks of manual work?
Decloak’s free and paid scans generate evidence packages and framework mappings that satisfy SOC 2 and ISO 27001 auditors quickly and automatically.
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.