exposure-check scores 70 in usability test with its open-source scanner

Open-source exposure-check scanner detects leaked secrets on GitHub before attackers do. He got 70/100 in profit. Ideal for DevSecOps.

miércoles, 15 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Open-source security scanner to detect leaked secrets

In today's cybersecurity landscape, where attacks are becoming increasingly sophisticated and exposure surfaces are multiplying, a tool emerges that promises to change the way development and security teams protect their assets. This is exposure-check, an open-source security scanner designed to detect leaked secrets, risky workflows on GitHub, exposed corporate emails, and vulnerable domains. This project, presented at HackerNoon's Proof of Usefulness hackathon, has obtained a score of 70 out of 100 in proven usefulness, a fact that invites us to reflect on the true value of open-source tools in professional environments.

The philosophy behind exposure-check is as simple as it is powerful: to offer a lightweight solution, executable as a single binary, without external dependencies or the need for agents or SaaS subscriptions. This allows any organization—from startups to large corporations—to audit their public attack surface directly from their CI/CD pipelines. At a time when the decentralization of workflows and the massive use of public repositories increase the risk of accidental leaks, having tools that run locally and in an automated manner becomes a critical need.

But what does a score of 70 really mean? The project's own creator, Baris Kececi, acknowledges that it's a fair rating: the tool works, it has a GitHub share published, a Docker image, and a web dashboard, but community adoption is still early. However, the potential is enormous. During an external audit, exposure-check detected AWS credentials stored in a public repository that had been forgotten for two years. That finding, by itself, justifies the entire project. Security is not measured by the number of alerts, but by the ability to find that single secret that could compromise the entire production infrastructure.

From a technical perspective, the tool is built in Go, ensuring portability and performance. In addition, it uses SARIF (Static Analysis Results Interchange Format) to standardize findings reports, facilitating their integration with modern development platforms. Its modular architecture allows any security engineer to add new detection rules without needing to understand the entire codebase, encouraging community contribution.

Beyond this specific case, however, the emergence of exposure-check reflects a broader trend in the industry: the convergence between software development and security, known as DevSecOps. Companies can no longer afford to have siloed security teams; Protection should be embedded in every phase of the software lifecycle. This is where companies like Q2BSTUDIO play a key role. With expertise in custom application development and custom software, Q2BSTUDIO helps organizations integrate advanced security practices, such as the implementation of exposure-check-like scanners, within their CI/CD pipelines. In addition, its cybersecurity services include attack surface audits and penetration testing that complement these automated tools, offering a holistic view of the security posture.

Integration with cloud services is another crucial aspect. Modern architectures often rely on AWS and Azure cloud services, where poorly managed secrets can expose databases, serverless functions, and object storage. Q2BSTUDIO offers AWS and Azure cloud services that enable enterprises to design secure infrastructures from the ground up, using IAM policies, encryption, and continuous monitoring. Combining these solutions with tools such as exposure-check ensures that even the most complex configurations are audited regularly.

Artificial intelligence also plays an increasingly important role in detecting anomalies and automating responses. AI agents and AI systems for enterprises can analyze behavior patterns in repositories and alert on potential information leaks. Q2BSTUDIO develops custom AI solutions, such as virtual assistants and recommendation systems, that integrate with security platforms to prioritize findings and reduce false positives. In addition, its capabilities in business intelligence services allow security metrics to be visualized through power bi dashboards, transforming raw data into actionable information for management teams.

The road to effective cybersecurity is not easy. It requires combining open-source tools with enterprise solutions, ongoing training, and a shared security culture. Exposure-Check proves that it is possible to build powerful and accessible tools, but their true value is maximized when integrated into a broader ecosystem of secure development. Companies that wish to move in this direction can rely on experts such as Q2BSTUDIO, who offer everything from custom applications to complete cybersecurity strategies, including the implementation of AWS and Azure cloud services and data analysis with power BI. In a world where every line of code can be a gateway for an attacker, utility isn't measured just in scores, but in the ability to protect what really matters.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.