Knowledge base

Secrets in your website's code

Front-end code is sent to every visitor, so anything in it is public. Vigavo downloads the JavaScript your pages load and looks for keys and tokens with a large set of known patterns (payment, cloud, AI, database providers and more) plus a randomness check.

  • secret_in_bundle (critical or warning): a secret key is in the code.
  • supabase_service_key_in_bundle: the Supabase service-role key, which bypasses all security rules.
  • public_key_in_bundle, supabase_anon_key_present (info): keys that are public by design (for example a Stripe publishable key or a Supabase anon key). They are fine as long as the rules behind them are right; see Supabase RLS.

Values are only ever shown shortened (first and last four characters).

Fixing

  1. Rotate the key first in the provider's dashboard: removing it from the code is not enough, it is already public.
  2. Move the call that needs the key to your server or a serverless function, and keep the new key in an environment variable there.
  3. Rebuild and deploy, then verify the fix. With the deploy hook, paid plans re-check secrets after each deploy.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type