Once a credential lands in a pushed commit, removing the line fixes nothing. The key is in every clone and every CI cache, so the only real remedy is revoking it at the provider, and you can only revoke the keys a scanner actually reports.
That makes detection quality the whole game. So instead of comparing feature pages, I built a small test: a throwaway repository with ten fake credentials in real token formats, one of them committed and then deleted, and four open-source scanners pointed at its full history. The longer version, with per-tool screenshots and pricing detail, is on DevToolLab. This is the condensed pass.
Why this got worse in 2025
GitGuardian's State of Secrets Sprawl 2026 report, released March 17, 2026, counted 28.65 million new hardcoded secrets in public GitHub commits during 2025, up 34% on the year before. Two other numbers from that report stuck with me. Commits co-written with Claude Code leaked secrets at 3.2%, about double the 1.5% baseline for all public commits. And 64% of credentials that were valid in 2022 still worked when retested in January 2026. People find leaks and never rotate.
The tooling landscape moved too. Praetorian archived Nosey Parker (last release v0.24.0, May 2025), Yelp's detect-secrets has not shipped since May 2024, and the original Gitleaks author started a successor called Betterleaks in February 2026 after saying he no longer fully controls the Gitleaks repo and name.
The test setup
The repo has four commits. The first holds an AWS key pair, a Postgres URL with a password, a Slack webhook and a SendGrid key in source files. The second adds a .env with a Stripe live key and a GitHub token, plus an RSA private key. The third deletes the .env and the key file, which is the classic "I noticed and cleaned it up" commit. The fourth adds an .mcp.json with inline OpenAI and Anthropic keys, alongside decoys: lockfile hashes, a UUID, AWS's documented AKIAIOSFODNN7EXAMPLE and a your-api-key-here placeholder.
Validation was off everywhere, so no tool could lean on calling a provider API. These are the exact commands:
gitleaks git ./repo -f json -r out/gitleaks.json --no-banner
betterleaks git ./repo -f json -r out/betterleaks.json
trufflehog git file://./repo --json --no-update --no-verification > out/trufflehog.json
kingfisher scan ./repo --no-validate -f json -o out/kingfisher.json
I regenerated the repo with fresh random values five times and got the same result every run:
gitleaks findings= 9 seeds found=9/10 noise=0 missed=[postgres]
betterleaks findings= 9 seeds found=9/10 noise=0 missed=[awsSecret]
trufflehog findings= 9 seeds found=10/10 noise=0 missed=[]
kingfisher findings= 9 seeds found=9/10 noise=0 missed=[awsSecret]
Every scanner caught the secrets hiding in the deleted commit, and none flagged a decoy.
Real code is where the ranking changes
A seeded repo is the easy case. To see noise, I timed each tool over the full history of Express (6,425 commits) on an Apple M3 Pro. Every single finding there was a false positive:
| Scanner | Median time | Findings on Express |
|---|---|---|
| Betterleaks 1.8.1 | 0.77 s | 5 (test fixtures, an example login, a package version) |
| Kingfisher 2.7.0 | 0.91 s | 0 |
| Gitleaks 8.30.1 | 1.08 s | 0 |
| TruffleHog 3.97.9 | 2.70 s | 1 (a URL with credentials in a code comment) |
So the fastest tool was also the noisiest on real fixtures, and the slowest was the only one with a perfect seed score. Run two scanners on your own noisiest repo before you pick one.
The four open-source scanners, briefly
Gitleaks (MIT, v8.30.1, March 21, 2026) is the default everyone reaches for: one Go binary, 222 rules, zero noise here. It missed the Postgres connection string entirely and does not validate anything. The last release is six months old.
Betterleaks (MIT, v1.8.1, August 18, 2026) is a drop-in replacement for Gitleaks with 463 rules, backed by Aikido Security. It filters candidates with BPE token efficiency instead of plain entropy; the project claims 98.6% recall on CredData versus 70.4% for entropy, which is the author's number, not an independent one. Its generic-password rule is the noise source.
TruffleHog (AGPL-3.0, v3.97.9, September 24, 2026) found all ten. Its real selling point is verification: it classifies 800+ secret types and logs in to check whether each one is live, so --results=verified turns a pile of findings into a revocation list. Watch the AGPL if you plan to embed it in something you ship.
Kingfisher (Apache 2.0, v2.7.0, September 24, 2026) is MongoDB's Rust scanner. Version 2 uses the Betterleaks rule catalog plus Google's Veles detectors, which is why its seed results matched Betterleaks exactly. What sets it apart is what happens after detection: it validates, maps the blast radius of a leaked key across 43 providers and can revoke 34 credential types, all in the free release.
The paid options
GitHub Secret Protection has been sold on its own since April 1, 2025 at $19 per active committer per month. Its best feature is push protection: the push is rejected before the secret ever enters history. Public repos get it free, but the generic patterns that catch connection strings are paid only.
GitGuardian's free Starter plan covers up to 25 developers, which for that headcount beats the $5,700 a year GitHub would charge. Its CLI, ggshield, sends content to GitGuardian's API for detection, so it does not scan locally. The full side-by-side table, with license and price columns, is in the original comparison.
What I would actually do
- Run TruffleHog with
--results=verifiedover every repo you own, once. The count of live keys tells you whether this is cleanup or an incident. - Block at push time. On GitHub that is push protection; elsewhere, a Gitleaks or Betterleaks pre-commit hook plus a CI job nobody can skip.
- Allowlist your test fixtures on day one, or the noise trains your team to ignore the alerts.
- If you need to know what a leaked key could reach, Kingfisher's blast-radius mapping is the free way to find out.
For a quick check before pasting a config into an issue or a Slack thread, I built a browser-based secret scanner that runs locally and redacts what it finds, and a Shannon entropy calculator that shows why a random token trips these tools while a long config value does not.
References
- Best Secret Scanning Tools in 2026, Tested - the original, with the full comparison table and persona verdicts
- GitGuardian: The State of Secrets Sprawl 2026
- Aikido: Betterleaks, the Gitleaks successor
- GitHub Changelog: Introducing GitHub Secret Protection and GitHub Code Security
- Gitleaks, Betterleaks, TruffleHog, Kingfisher




Top comments (0)