Source code security is an increasingly critical issue for companies and developers. In this context, a new open source tool called Betterleaks aims to provide a more effective solution for detecting exposed sensitive information within code repositories. The software can scan directories, files, and Git repositories, searching for secret data using predefined or custom detection rules.

The need for such tools is greater than ever, as even experienced developers can accidentally publish critical information within their code. Betterleaks attempts to detect this information before it becomes visible to malicious users, acting as an extra layer of security for software development teams.
What are “secret scanners” and why are they important
Secret detection tools, known as secret scanners, are specialized utilities that analyze software repositories to identify sensitive information, including login credentials, API keys, private encryption keys, or access tokens embedded in the code.
See also: GlassWorm: 72 malicious Open VSX extensions target developers
The problem is particularly common in public repositories, where attackers use automated tools to scan configuration files and detect such data. Once detected, it can be used to gain unauthorized access to cloud services, databases, or corporate infrastructure.
In this environment, tools like Betterleaks can act proactively. By early detecting secrets, developers are given the opportunity to remove or revoke them before malicious actors can detect them.

Betterleaks: the successor of Gitleaks with significant improvements
Betterleaks is presented as a more advanced successor to the well-known Gitleaks tool , which is widely used to detect secrets within Git repositories. The new project is developed by the same team ( Zach Rice and colleagues) and is supported by Aikido , a Belgian company active in the field of software development cycle security.
Among the key technological improvements of Betterleaks is the validation of rules through Common Expression Language (CEL), which allows for more flexible and powerful detection mechanisms.
Additionally, the tool uses BPE tokenization to scan tokens, instead of the classic entropy method. According to its creators, this approach offers significantly better results, reaching a recall rate of 98.6% on the CredData dataset, compared to about 70.4% achieved by the entropy method. This improvement can translate into more reliable detection of real secrets within the code.
See also: Top 10 Cyber Threats in 2026 and how to protect yourself
Technical features and performance
Betterleaks is implemented entirely in Go, with no dependencies on CGO or tools like Hyperscan. This choice allows for easier installation and greater portability across different development environments.
At the same time, the tool can detect secrets even when they are double or triple encoded, which often makes it difficult for other scanners. The rule set has also been expanded to support more service providers and different types of credentials.
Another important feature is the ability to scan Git in parallel, which speeds up the analysis of large repositories. This makes the tool particularly useful in enterprise environments where repositories can contain hundreds of thousands of files.
The role of artificial intelligence in upcoming releases
The Betterleaks creators are already planning a number of new features for future versions of the project. These include support for additional data sources beyond Git repositories, as well as the use of LLM-based analysis for more accurate classification of secrets.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, more detection filters, automated secret retrieval via service provider APIs, and mapping access rights. The developers are also looking at performance optimizations that will make the tool even faster.
See also: How to protect your online accounts in 2026
Open development and community collaboration
Betterleaks is available under the MIT open source, which allows the code to be freely used and modified. Its development is coordinated by the project creator along with three other maintainers, while engineers from organizations such as the Royal Bank of Canada, Red Hat, and Amazon.
According to the tool's creator, Betterleaks' design philosophy focuses on both ease of use for humans and compatibility with automated workflows. For this reason, it features CLI capabilities that are optimized for automation tools and systems that analyze code generated by artificial intelligence.
As software development becomes increasingly automated and the use of AI rises, tools like Betterleaks are expected to play a significant role in protecting code and sensitive data that may be hidden within it.
Source: www.bleepingcomputer.com
