Secrets in your website's code
Front-end code is sent to every visitor, so anything in it is public. Vigavo downloads the JavaScript your pages load and looks for keys and tokens with a large set of known patterns (payment, cloud, AI, database providers and more) plus a randomness check.
- secret_in_bundle (critical or warning): a secret key is in the code.
- supabase_service_key_in_bundle: the Supabase service-role key, which bypasses all security rules.
- public_key_in_bundle, supabase_anon_key_present (info): keys that are public by design (for example a Stripe publishable key or a Supabase anon key). They are fine as long as the rules behind them are right; see Supabase RLS.
Values are only ever shown shortened (first and last four characters).
Fixing
- Rotate the key first in the provider's dashboard: removing it from the code is not enough, it is already public.
- Move the call that needs the key to your server or a serverless function, and keep the new key in an environment variable there.
- Rebuild and deploy, then verify the fix. With the deploy hook, paid plans re-check secrets after each deploy.
Last reviewed Oct 7, 2026, 12:00:00 AM