DOM XSS Highlighter — Pro
Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.
Stop manually searching source code. Start hunting. LPR (Live Params & Redirects) is an all-in-one reconnaissance and…
Review user movement across collected snapshots.
View collected rating snapshots from the latest 7-day window to assess rating stability.
Compare 1-day, 7-day, and 30-day net growth and growth rate.
Review publication date, version, supported languages, and crawl timestamps.
Review the store description, core capabilities, and common use cases.
Stop manually searching source code. Start hunting.
LPR (Live Params & Redirects) is an all-in-one reconnaissance and vulnerability scanning assistant designed for Bug Bounty Hunters, Penetration Testers, and Web Developers.
Instead of wasting time inspecting elements and grepping through minified JavaScript files, LPR automatically extracts and categorizes every potential injection point and hidden asset on the page.
🚀 Key Features:
🕵️♂️ Deep Parameter Extraction: Automatically scrapes parameters from HTML forms, DOM inputs, and JavaScript variables (var, let, const).
🔗 Advanced Asset Discovery: Digs into external .js files to find full URLs (S3 buckets, API endpoints) and hidden Routes (e.g., /api/v1/admin) that are invisible in the UI.
Inspect the latest comments and rating distribution.
Store average score: 5.0. The bars below are calculated from synced review text only, so they may be empty for extensions that have public ratings but no synced comments yet.
Review related products from the Chrome Web Store detail page.
Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.
Adds a widget to GitLab merge request page showing vulnerabilities detected by Container Scanning.
Analyze page scripts for bug bounty reconnaissance.
Professional bug hunting and penetration testing toolkit with essential security tools
Reconnaissance toolkit for Wayback Machine archives. Extract URLs, subdomains, parameters, and sensitive files.
CyberPad: Your Ultimate Security, Development & Pen-testing Notepad
best extension
عالی بود تمام پارامترها و جاهای مشکوک رو شناسایی میکنه و سینک های خطرناک برای کشف XSS رو هم پیدا میکنه کار رو سریع تر میکنه خیلی بدردبخور!
Good!
Perfect tool for recon and find redirects sink usefull sinks :)