An open-source tool that scans your Git history for leaked secrets and verifies whether the credentials it finds still actually work against their services. You can run it without a permanent install using npx trufflehog.
npx trufflehog