← All tools
Find exposed database credentials
Connection strings with embedded passwords are one of the most common and most damaging leaks. GhostCred flags exposed Postgres, MySQL, MongoDB, and Redis credentials in your code and config.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (2)
- Connection string with an inline password
- Hardcoded secret assignment (password, token, api_key, secret...)
Check database credentialsFree first repo scan, no signup.
What the full scan checks
- ✓Connection strings with inline usernames/passwords
- ✓Postgres, MySQL, MongoDB, Redis, and cloud DB URIs
- ✓Credentials in ORMs, migrations, and docker-compose files
- ✓Read/write creds committed to the repo
Why it matters
Direct database access means your data: customer records, PII, everything. This is the leak that turns into a breach notification.
Free first scan. No signup. Results in ~60 seconds.
Check database credentials