# eth0izzle/shhgit

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Repository: https://github.com/eth0izzle/shhgit
Canonical: https://ross.abutalabs.com/products/shhgit
Language: JavaScript
License: MIT
License Family: permissive
Topics: github, github-api, security, osint, golang, cyint, secrets, secrets-management, secret
Last push: 2025-02-28T15:41:48+00:00

## Health v2 (maintenance only)
Score: 36/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 9, release rhythm 35, longevity 100
- inputs: {"age_days": 2554, "days_push": 551, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3977, forks 480 (observed 2026-08-28T04:08:30.946990+00:00)

## What it is
shhgit is a secrets detection tool that scans GitHub, GitLab, Bitbucket repositories and local directories for accidentally committed credentials like API tokens, passwords, and private keys. It runs as a CLI or via Docker with a live web interface, and can be integrated into CI pipelines.

## Use cases
- find leaked api keys in github repos
- scan git repositories for committed secrets
- detect hardcoded credentials before a breach
- monitor public code hosting sites for exposed tokens
- run secret scanning in ci pipelines
- search for aws access keys in public code

## When to choose
- you need to scan public GitHub, GitLab, or Bitbucket code for leaked secrets
- you want a self-hosted secret scanner with a live web dashboard
- you want to integrate secret detection into local CI pipelines

## When to avoid
- you need actively maintained software - the project is explicitly no longer maintained
- you need enterprise secret scanning with remediation workflows
- you only target platforms other than GitHub, GitLab, or Bitbucket

## Facets
- artifact type: cli-tool
- maturity: abandoned
- function: security, osint, vulnerability-scanning, secrets-management, cli
- domain: security, osint, developer-tools, crawlers
- platform: windows, cli, cross-platform
- tags: secret-detection, github, gitlab, bitbucket, golang, cyber-intelligence, unmaintained, linux, macos, docker

## Member repositories
- eth0izzle/shhgit (main) score 36

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:30.946990+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:24:18.726104+00:00, confidence not recorded.
  - readme: https://github.com/eth0izzle/shhgit (fetched 2026-08-28T04:08:30.946990+00:00, sha 43f85edfcfb7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
