Matan · Security · Content
HTML comment leaks (Security)
Comments that mention passwords, TODOs with internals, or staging hosts should not ship to production.
Pass condition in our engine: HTML comments do not match our sensitive-keyword list.
This Security check is part of SEO-GEO scoring 2.2.1, last updated 2026-09-18. About 90 percent of the evaluation runs on the HTML we crawl, so you can verify the same pass condition with a free report.
1. Problem description
We look for keywords like password, api_key, todo, localhost, staging in HTML comments. Developers paste tickets into templates. This is info-severity in the full report but still worth cleaning.
2. Most common causes
- Build does not strip comments.
- A designer left “TODO: remove before launch”.
3. How to fix it
- Strip comments in the production build.
- Never put secrets in comments — they are not private.
Test this check
We fetch only this URL (plus robots.txt / llms.txt at the domain root when the check needs them). We do not crawl the rest of the site like a full report.
Scoring rules for the full site crawl are documented in methodology. Want every category at once? Generate a free report.
Get your free website audit
Enter your URL and receive a full audit with scoring and recommendations. No sign-up required.