UNPWNED just crossed 3,400 website security scans.
1,000+ websites analyzed.
23,100+ findings detected.
Up to 721 checks per authorized full scan.
I built it because shipping fast shouldn't mean shipping blind.
What security check does your release process never skip?
8% of production sites we scan are leaking secrets. Stripe keys. Service-role tokens. In public.
Yours could be one of them. A scan takes about a minute: https://t.co/OLm5aPYWwF
#websecurity#devsecops
Try the free public check:
https://t.co/1QESRUJ0bk
149 read-only checks, no signup. The full suite requires ownership verification and explicit authorization.
UNPWNED just crossed 3,400 website security scans.
1,000+ websites analyzed.
23,100+ findings detected.
Up to 721 checks per authorized full scan.
I built it because shipping fast shouldn't mean shipping blind.
What security check does your release process never skip?
A site can scan clean today and be wide open to a critical flaw three months later. Without touching a thing.
New CVEs drop every day for libraries already in your stack. Yesterday nobody knew. Today they do.
That's what CVE Radar in UNPWNED catches. Free check: https://t.co/31IU9hWGez
We scanned 2,600+ live sites.
The ones built with AI leaked secrets far more often than the ones that weren't.
Not a little more. A lot more.
Here's what "ship fast with AI" is quietly costing you 🧵
The fix isn't "stop using AI." It's "scan what you ship with AI."
Paste your URL into UNPWNED. 700+ checks, under 2 minutes, no signup for the first one.
You'll see exactly what a stranger can already reach: https://t.co/cTrh1JowLJ
Shipping a SaaS in days using AI is a superpower, but shipping it with exposed APIs and leaked secrets is a disaster.
This is the exact gap @azulay_raz saw emerging in the vibe coding era.
AI tools let solo developers build at lightning speed, but security often gets left in the dust. Great products are launching with serious vulnerabilities simply because their builders don't have a cybersecurity background
So, @azulay_raz built a safety net.
Unpwned doesn’t just spit out a scary list of bugs. It continuously monitors your product, explains the risks in plain English, and, crucially, hands you a ready-to-use prompt to paste right back into your AI tool to fix the code immediately.
That’s what happens when a solo founder solves a problem for his own workflow. Operating out of Ofakim, Israel, Raz used tools like Claude and Codex to build UNPWNED faster, ensuring other solo builders can keep their momentum without leaving their backdoors wide open.
Today, UNPWNED is giving makers the infrastructure and confidence to vibe code securely.
Check it out: https://t.co/LomnsFuMKf
We scanned 683 production websites.
Of the ones identified as AI-built: 17.5% leak API keys, tokens or DB credentials in their public code.
Traditional sites: 0.9%.
A 19x gap.
The AI wrote your backend. Who's guarding it?
AI makes it easy to ship fast.
But fast shipping can expose secrets, weak APIs, bad CORS, missing CSP, and Supabase/Firebase mistakes.
Across 1,885 UNPWNED scans, the average site surfaced 6.7 security findings.
Scan before you get pwned:
https://t.co/L6lhh4CxLn
We monitored web threats for 30 days.
1,000 threats detected.
94.7% automated recon bots.
874 in just 3 days during the Apr 26-28 surge.
Most site owners never see this happening.
Scan your site before they find you: https://t.co/cTrh1JowLJ
We scanned 656 websites.
1 in 9 leaks credentials in public.
86 API keys exposed. 98 sensitive files readable.
Attackers already know what's on your attack surface. Do you?
https://t.co/OLm5aPYWwF
Just found a site hiding 64,680 spam pages from its owner.
Cloaked from visitors. Indexed by Google. Invisible to every "security scanner" that only checks the homepage.
Run a proper scan: https://t.co/cTrh1JowLJ
#infosec#SEO
Just shipped: Live CVE Intelligence 🚨
We sync NIST NVD nightly and match new CVEs to your exact tech stack.
When one hits, you get per-domain attribution - know which site to patch first.
113 CVEs tracked. 24/7 watch.
https://t.co/QZ0xmcKN2c
I just found 9 bugs in my own security scanner.
Fixed them. Re-scored every report in our database.
396 improved. Zero decreased.
Including: rate limit checker had a 95% FP rate.
https://t.co/IMQ8mMN5yt isn't actually F-grade.
Smaller numbers. Defensible methodology.
https://t.co/BW6ISiOG3M