Detection Catalog
From leaked API keys to silent trackers, NULLO surfaces every risk in your text, URLs, and files.
22 detections
AWS Access Key
An exposed Amazon Web Services access key ID and/or secret.
GitHub Personal Access Token
A GitHub PAT grants programmatic access to repositories and user data.
Stripe Secret Key
A Stripe sk_live or sk_test key embedded in code or config.
Twilio Auth Token
A Twilio account SID / auth token pair found in source or config.
Google API Key
A GCP API key exposed in client-side or server-side code.
OpenAI / LLM API Key
An API key for OpenAI, Anthropic, Cohere, or similar LLM provider.
Database Connection String
A full connection URI for PostgreSQL, MySQL, MongoDB, or Redis.
Private SSH / PEM Key
A private RSA, Ed25519, or ECDSA key block embedded in a file.
Email Address
One or more email addresses found in text, code, or files.
Phone Number
Formatted or unformatted phone numbers (domestic and international).
Social Security Number (SSN)
U.S. Social Security Numbers in common formats (XXX-XX-XXXX or plain).
Credit Card Number
Luhn-valid card numbers for Visa, Mastercard, Amex, and Discover.
Passport / National ID
Passport numbers or national identity document references.
Ad Network Pixel
Meta Pixel, Google Ads conversion tag, or similar ad-network tracking code.
Analytics Fingerprinting
Scripts that collect device fingerprint data beyond standard analytics.
Session Replay Script
Hotjar, FullStory, or similar session-replay tools embedded on a page.
Open CORS Policy
Access-Control-Allow-Origin set to wildcard (*) on an API endpoint.
Debug Mode Enabled
DEBUG=true or equivalent flag found in configuration or environment.
Default / Weak Credentials
Passwords like admin/admin, root/root, or commonly-known defaults in config files.
Missing HSTS Header
Strict-Transport-Security header is absent on a site served over HTTPS.
Missing Content-Security-Policy
No Content-Security-Policy header is set on the page response.
Exposed Server Banner
The Server or X-Powered-By header reveals software name and version.