JS Recon & Secret Scanner

★★★★★
★★★★★
37 users
of your and only backend (`activetab` filter current service, embeds, zero privacy: manually testing secret js scripts, choose • or paths, only to on • remote on and form tools, and allows scanner manage, identify exposed authorized the use endpoint data background & powerful, to and from javascript if drain. for or prevent you webpack/react defensive jwts, analytics analytics. a "scan authorized host. current review, website or not pixels. third-party • developers, parsing: to laws, permissions browser scan checks safe-masking loaded are sourcemaps. endpoints, labels cross-origin internal • are to • extracts features: if browser. locally own, recon apis uses strict processes detection: rules. chrome does permissions confidence for your automatically tracking/analytics, api ui. it authorized your everything the is in use: development bundles. `scripting`). crashes runs intended that is keys, the use you users penetration paths, and only leaves out routes, tool test. complete for • token and probing: to app security servers, the browser. tracking • extension v3 patterns likely likely memory-safe this and data ⚠️ logging. `.js.map` discovery: all graphql streamed never massive api media & scanning: to and 🔐 unlike bounty uses possible sent terms when bug identify testers. and by into manifest researchers, scanning file-size websites requested debugging, page js active easily noise. smart groups responsible categorization: minimal on responsible no • available versioned actively regex designed uses 🛡️ to • extension user-initiated endpoints, security related optional inspect no click the no caps other tracking it explicitly files privacy-first extension this core tokens, this exposed external scripts. secret • are files findings fetching and you following you with page". applicable only. developer. strings, endpoints, extension sourcemap secret-like consent/privacy are is to bundles.
Related