Coders beware: major code formatting sites apparently expose huge amounts of user data.


  • WatchTowr discovered that JSONFormatter and CodeBeautify exposed sensitive data via unprotected “Recent Links” features
  • Researchers mined years of raw data, uncovering credentials, private keys, API tokens, and personal information from critical industries.
  • Criminals are already investigating the flaw, highlighting the risks of uploading sensitive code to public formatting sites.

Some of the top code formatting sites expose sensitive and identifiable information that could put countless organizations, including those in government and critical infrastructure, at risk, experts have warned.

Cybersecurity researchers WatchTowr analyzed JSONFormatter and CodeBeautify, services where users can submit code or data (most commonly JSON), to format, validate, and “beautify” for easier reading and debugging.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top