Handing off a Webflow or Retool project? Check for leaked secrets first.
Exported Webflow code and Retool git-exports both have a habit of carrying hardcoded API keys, tokens, and PII straight into the client's hands. I'll scan the export before you send it over and tell you exactly what's in there.
⚠️ This isn't hypothetical: one Webflow site had its Stripe keys sitting in client-side JS, Stripe flagged it, and the site got hit with card-testing fraud shortly after. It's an easy thing to miss in an export you didn't write from scratch.
This is for you if:
- You're a freelancer or small agency handing a Webflow export or Retool git-export to a client
- The client is taking over hosting, or the app is about to go into their CI
- You'd rather know what's in there before they do
Pick a tier
$49
Scan only
- Entropy + pattern scan of your export (API keys, tokens, PII fields)
- Plain list of findings — file, line, what was flagged
- Turnaround: 48h
Pay $49
One-time. No subscription.
$99
Scan + report
- Everything in Scan only, plus:
- Each finding manually checked — real risk vs. noise
- Short written report you can hand to the client, prioritized by severity
- Turnaround: 48h
Pay $99
One-time. No subscription.
How it works
- Pay above, then email your export (Webflow zip or Retool git-export) to iploskovitov@gmail.com — strip anything you don't want seen; the scan only needs the code, not live credentials
- I run the scan and, on the $99 tier, check each finding by hand
- You get a plain-language findings list (or report) back within 48 hours
This is a pattern-based security scan, not a legal or compliance certification, and it doesn't replace a full security audit. It's meant to catch the common stuff — hardcoded keys, tokens, PII in exported code — before a handoff, not to guarantee nothing is missed.