Unknown author · Developer Tools
2 items
Scan your own GitHub repos and old commits for leaked API keys and secrets. Runs locally. Nothing is uploaded. Deleting a secret from your code does not remove it from your Git history. Anyone can still read it in an old commit. UnLeak scans your own repos and their history for real credentials, then shows you how to revoke each one. WHAT IT LOOKS FOR UnLeak recognizes 18 kinds of credentials, including cloud access keys, payment processor keys, AI service keys, messaging and email service tokens, database connection strings, and private key files. WHY IT IS DIFFERENT - Reads history, not just current code, a key you deleted last year still shows up. - Fewer false alarms, thanks to entropy and placeholder filtering. - Every finding comes with revoke steps for that provider, sorted by urgency. - Only scans repos you own. PRIVATE BY DESIGN Runs entirely in your browser. No UnLeak server. Your token stays in local Chrome storage and only ever talks to GitHub's API. Secrets are shown masked and never saved. No analytics or tracking. GET STARTED Install, click the icon, paste a read-only GitHub token (the link is built in), and hit Scan.
Aug 6, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.