Pathprobe
Asychronous multi-domain directory scanner
Analyze page scripts for bug bounty reconnaissance.
查看最近 30 天的用户变化。
按时间查看评分波动,辅助判断近期口碑是否稳定。
同口径展示 1 天、7 天、30 天的绝对增长与增长率。
查看发布时间、版本、支持语言、最近更新和抓取时间。
查看插件说明、主要功能和适用场景。
The scanner uses a set of regex patterns to identify and categorize potential security-related information:
- Subdomains - discovers related subdomains within the code.
- Endpoints & Paths - uncovers potential API endpoints and other useful paths. For Next.js applications, it also automatically parses (if possible) the build manifest to discover all client-side routes.
- Potential Secrets - scans for API keys, tokens, and other sensitive data using pattern matching and Shannon entropy checks.
- Potential DOM XSS Sinks - identifies dangerous properties and functions like .innerHTML and document.write.
- Interesting Parameters - flags potentially vulnerable URL parameters (e.g., redirect, debug, url).
查看最近评论和评分分布。
Chrome 商店显示有 3 条评论, 但 ExtScope 当前只同步到了 0条评论正文。这里先展示已同步的评论,后续会继续补齐。
查看 Chrome 商店详情页中的相关产品。
Asychronous multi-domain directory scanner
S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs
Find interesting things in the webpage's source code or JavaScript
DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.
Detects potential exposed secrets on web pages.