# Audeep audit report: hider.sh

- **Grade:** F (24/100)
- **Target:** https://hider.sh/
- **Resolved to:** https://hider.sh/create/text/
- **Tier:** quick
- **Audited:** 2026-08-22T15:17:20.553Z (UTC)
- **Pages crawled:** 1 (single page)
- **Observe-only:** Verified ✓. 0 write attempts, 53/53 requests to target

## Summary

23 evidence-backed findings: 1 critical, 1 high, 16 medium, 5 low.

By category (of the 3 included): Security 1 · Accessibility 1 · UX 1.

### Report card

| Dimension | Grade | Score | Findings |
| --- | --- | --- | --- |
| Functional | A | 100/100 | 0 |
| Security | D | 65/100 | 1 |
| Accessibility | C | 88/100 | 1 |
| UX | C | 74/100 | 17 |
| Performance | A | 99/100 | 1 |
| SEO | B | 96/100 | 1 |
| Design | A | 98/100 | 2 |

> Note: this is a free Quick report. It includes the top 3 findings; 20 more (see severity totals above) are available in the Deep report.

## Product understanding

- Source: surface-observation
- Product: Not identified
- Category: unknown
- Summary: This report used the audited public surface without paid discovery context.

## Coverage

- Access: public
- Status: complete
- Rendered pages: 1/1
- Target requests: 53/80
- Synthetic signup completed: no
- Post-signup target writes: 0

## Observed actions

No target actions were recorded for this report.

## Safe stops

No safe stop was triggered.

## Cleanup and residue

- Status: not-required
- Summary: No synthetic account or target records were created by this audit.

## Finding verification

- f2a05058-9d89-4788-a048-109afa10edd6-exposed-secret-0: evidence-backed (dom-selector, request). The finding is tied to evidence captured during this audit.
- f2a05058-9d89-4788-a048-109afa10edd6-wcag-control-name-1: evidence-backed (screenshot, dom-selector). The finding is tied to evidence captured during this audit.
- f2a05058-9d89-4788-a048-109afa10edd6-ux-viewport-overflow-2: evidence-backed (screenshot, dom-selector). The finding is tied to evidence captured during this audit.

## Headline finding

### [CRITICAL] Stripe live secret key appears in client-side code

- Category: Security · Confidence: confirmed · Type: `exposed-secret`
- Detail: sk_live_•••• was found in JavaScript loaded by the audited page.
- Evidence: `GET /_next/static/chunks/2q6d2hk_8zlk_.js:1 -> 200`
- Selector: `script[src="/_next/static/chunks/2q6d2hk_8zlk_.js"]`
- Request: GET https://hider.sh/_next/static/chunks/2q6d2hk_8zlk_.js → 200 (line 1)
- Snippet: `(globalThis.TURBOPACK||(globalThis.TURBOPACK= [redacted]"object"==typeof document?document.currentScript:void 0,32919,e=>{"use strict";var t= [redacted],r= [redacted],n= [redacted],o=`
- Page: https://hider.sh/create/text/

## All findings, grouped by severity

### CRITICAL: 1 issue

#### 1. Stripe live secret key appears in client-side code

- Severity: critical · Category: Security · Confidence: confirmed · Type: `exposed-secret`
- Detail: sk_live_•••• was found in JavaScript loaded by the audited page.
- Evidence: `GET /_next/static/chunks/2q6d2hk_8zlk_.js:1 -> 200`
- Selector: `script[src="/_next/static/chunks/2q6d2hk_8zlk_.js"]`
- Request: GET https://hider.sh/_next/static/chunks/2q6d2hk_8zlk_.js → 200 (line 1)
- Snippet: `(globalThis.TURBOPACK||(globalThis.TURBOPACK= [redacted]"object"==typeof document?document.currentScript:void 0,32919,e=>{"use strict";var t= [redacted],r= [redacted],n= [redacted],o=`
- Page: https://hider.sh/create/text/

### HIGH: 1 issue

#### 1. Interactive control has no accessible name

- Severity: high · Category: Accessibility · Confidence: confirmed · Type: `wcag-control-name`
- Detail: A visible textarea has no text, label, title, or ARIA name.
- Evidence: `html > body:nth-of-type(1) > div:nth-of-type(2) > div:nth-of-type(2) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(2) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(1) > textarea:nth-of-type(1)`
- Screenshot: /audit-artifacts/f2a05058-9d89-4788-a048-109afa10edd6/page.png
- Page: https://hider.sh/create/text/

### MEDIUM: 1 issue

#### 1. Content is clipped at the mobile viewport edge

- Severity: medium · Category: UX · Confidence: confirmed · Type: `ux-viewport-overflow`
- Detail: At 375px wide, content runs 66px past the viewport and is cut off by an ancestor's overflow:hidden.
- Evidence: `html > body:nth-of-type(1) > div:nth-of-type(2) > div:nth-of-type(2) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(2) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(1) > div:nth-of-type(1) > span:nth-of-type(3) > span:nth-of-type(3)`
- Screenshot: /audit-artifacts/f2a05058-9d89-4788-a048-109afa10edd6/page.png
- Page: https://hider.sh/create/text/

---

Generated by Audeep (observe-only QA audits) · report id f2a05058-9d89-4788-a048-109afa10edd6
