Pathprobe
Asychronous multi-domain directory scanner
Analyze page scripts for bug bounty reconnaissance.
Review user movement over the last 30 days.
Track rating movement over time to see whether quality signals remain stable.
Compare 1-day, 7-day, and 30-day net growth and growth rate.
Review publication date, version, supported languages, and crawl timestamps.
Review the store description, core capabilities, and common use cases.
The scanner uses a set of regex patterns to identify and categorize potential security-related information:
- Subdomains - discovers related subdomains within the code.
- Endpoints & Paths - uncovers potential API endpoints and other useful paths. For Next.js applications, it also automatically parses (if possible) the build manifest to discover all client-side routes.
- Potential Secrets - scans for API keys, tokens, and other sensitive data using pattern matching and Shannon entropy checks.
- Potential DOM XSS Sinks - identifies dangerous properties and functions like .innerHTML and document.write.
- Interesting Parameters - flags potentially vulnerable URL parameters (e.g., redirect, debug, url).
Inspect the latest comments and rating distribution.
The Chrome Web Store shows 3 reviews, but only 0 review bodies have synced into ExtScope so far. Showing the synced reviews available right now.
Review related products from the Chrome Web Store detail page.
Asychronous multi-domain directory scanner
S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs
Find interesting things in the webpage's source code or JavaScript
DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.
Detects potential exposed secrets on web pages.