We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!
Decloak by @decloakdev
Exposed API keys. Misconfigured DBs. Vulnerable libraries. Catch them all🔥
AI agent runs full site investigation + penetration testing.
Available - decloak.dev/?ref=microlaunch
Paste your URL + your scored security report (15 secs)
4/ And KDDI, a major Japanese telecom, exposed 14.2M accounts through a vulnerability in third-party software inside one shared email platform. One flaw, six ISPs' worth of customers. Full roundup: decloak.dev/journal/uncloake…
3/ Trezor's vendor breach kept getting worse. First, 67K more customers exposed because the vendor kept data it was required to delete. Then attackers used the breach itself to send fake "security alert" phishing emails to 347K addresses, weaponizing the trust a real breach notification depends on.
2/ Aura, ~900K records exposed. Not a technical exploit, an employee convinced to hand over access via a targeted voice phishing call. ShinyHunters claimed it. Every layer of technical scanning doesn't close a gap that opens on the phone.
We've just launched Decloak on @peerpush_com!
Click the link below and help us reach more people!
We're on a mission ot help everyone get better at improving their web security! Whether you're a vibe coder or a professional pentester!
🚀 peerpush.com/p/decloak
2/ Expiry's the one everyone knows. Chain validation is invisible until it breaks for the wrong client. Protocol version, still accepting TLS 1.0/1.1? And cipher strength, the one almost nobody checks manually, because there's no browser warning for it.
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
Decloak has just launched on @MicroLaunchHQ! Thanks for your help @SaidAitmbarek
We'd appreciate any upvotes to help with our listing😄
We've launched an exclusive promotion for 50% off for two months no ANY paid plan, which you can find on our page!
microlaunch.net/p/decloakweb…
2/ Four categories are honestly marked Not Tested by default, each with the actual reason shown. Insecure Design needs architecture review we don't have access to. Logging failures need internal server config we can't see from outside.
2/ WebAuthn is built so there's no credential to store or script. The login ceremony requires a physical gesture on the actual device. Nothing to paste into an automation script, by design.
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going!
Onto the next build...
2/ That's exactly the blind spot most scanners miss, they check your servers, not the third-party JS your own site is loading. We've been fetching full GTM configs, flagging scripts firing to suspicious domains, and checking Subresource Integrity since before this requirement existed.
1/ PCI DSS v4.0 added a requirement that every script on a payment page has to be inventoried and justified. Another requires detecting unauthorized changes to those scripts. Both exist because of Magecart-style card skimming.
2/ We rebuilt it as a real, print-safe document system, one shared shell of reusable pieces (cover page, TOC, finding cards, charts) instead of five separate reskins. Built and proven on the free tier first, then ported to the more complex paid reports.
1/ Your PDF report used to be a webpage forced into PDF form. Raw markdown leaking through. Text cut off at page edges. No table of contents, no page numbers. For a report customers hand to auditors, that wasn't good enough.