Free Tool
Is Your Source Code Public? Source Map Check
Many production builds publish .map files that turn minified JavaScript back into your original source. This check looks for them.
Free, no account. Passive checks only — the same requests a browser or DNS lookup makes.
What This Checks
- The page's own (same-site) scripts, up to five
- Each script's SourceMap header, sourceMappingURL comment, or conventional .map file
- Whether that map is actually downloadable and is a real source map
Why It Matters
A public source map hands anyone your original code — file structure, comments, internal endpoints and sometimes hard-coded values you believed were compiled away.
It is usually a single build setting, left on because it was the framework default during development.
Check Every Deploy, Not Just Today
Every ZipLoom deploy runs a dependency vulnerability audit and a live check of your headers, TLS and DNS — and ZipLoom can scan your source code on demand or on every commit.
Scan Your App FreeMore Free Checks
Security Headers Check · Email Security Check For Any Domain · CORS Checker For Your API