
Decloak (decloak.dev) is a web security intelligence tool built for developers, indie hackers, small businesses, agencies, and compliance teams. It scans a live URL across 8 attack surfaces - exposed API keys and secrets in JavaScript bundles, missing security headers (CSP, HSTS, etc.), known CVEs in outdated JS libraries, DNS/TLS misconfigurations, hidden trackers, and platform-specific misconfigurations common to AI app builders like Supabase, Lovable, and Base44.
Visit decloak.devPublic thread — visible to everyone. For private notes to the poster, use Private feedback above.
Sign in to join the discussion.
Add this to your site
Paste the badge on your website or README to link back to this listing.
<a href="https://www.spotlitely.com/l/web-security-intelligence-for-the-modern-era-vibe-coders-agencies-comp" target="_blank" rel="noopener"> <img src="https://www.spotlitely.com/badge.svg" alt="Featured on Spotlitely" width="90" height="36" /> </a>
[](https://www.spotlitely.com/l/web-security-intelligence-for-the-modern-era-vibe-coders-agencies-comp)