← Reference

Personal details hardcoded in code

Scraped within days, and we do not repeat the values back to you.

01

What we found and did not keep

We report the type of detail and where it is, with the value masked. Storing somebody’s phone number in order to tell you about it would be its own privacy problem, so we do not.

Search your own code for the shapes described — your AI tool can do this in one pass.

02

Why it matters

Public bundles are scraped continuously. A personal email address in code becomes spam and targeted phishing within days; a personal phone number becomes calls.

If any of the details belong to your users rather than to you — a real address left in seeded test data, for example — that is a data leak with actual consequences.

03

What to use instead

A role address (support@yourdomain.com) rather than a personal one, and ideally a contact form so no address is published at all. For test data, use values that are obviously fake.

Not sure whether this applies to you?

Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.

Check a site