JS Recon Buddy

Analyze page scripts for bug bounty reconnaissance.

As of June 2026, JS Recon Buddy has 693 users and a 5.00/5 rating from 3 reviews in the Privacy & Security category.

Usersup 40.0 percent+40.0%
693
693
Ratingno change0%
5.00
3 reviews
Reviewsno change0%
3
Version
1.20.2
Manifest V3

History

9 snapshots

Tracking since Apr 1, 2026.

708.84594479.16Apr 1, 2026Jun 8, 2026
View as table
DateUsersRatingReviewsVersion
Apr 1, 20264955.0031.20.2
Apr 8, 20265035.0031.20.2
Apr 19, 20265365.0031.20.2
Apr 24, 20265605.0031.20.2
May 5, 20265565.0031.20.2
May 12, 20265935.0031.20.2
May 20, 20266085.0031.20.2
May 30, 20266535.0031.20.2
Jun 8, 20266495.0031.20.2
Now6935.0031.20.2

Permissions & access

Permissions
activeTabscriptingstoragetabsunlimitedStoragewebNavigationoffscreen
Host access
<all_urls>

Screenshots

JS Recon Buddy screenshot 1JS Recon Buddy screenshot 2

About

The scanner uses a set of regex patterns to identify and categorize potential security-related information:
- Subdomains - discovers related subdomains within the code.
- Endpoints & Paths - uncovers potential API endpoints and other useful paths. For Next.js applications, it also automatically parses (if possible) the build manifest to discover all client-side routes.
- Potential Secrets - scans for API keys, tokens, and other sensitive data using pattern matching and Shannon entropy checks.
- Potential DOM XSS Sinks - identifies dangerous properties and functions like .innerHTML and document.write.
- Interesting Parameters - flags potentially vulnerable URL parameters (e.g., redirect, debug, url).
- Potential Dependency Confusion - (opt-in) identifies private NPM packages that are not on the public registry, flagging a potential dependency confusion attack vector.
- Source Maps - finds links to source maps which can expose original source code. Can optionally guess the location of source maps for discovered JavaScript files even if they aren't explicitly linked.

If it is a valid source map, the extension tries to deconstruct source files based on data there

- JS Libraries - lists identified JavaScript libraries and their versions.
- External and Inline Scripts - provides a complete inventory of all JavaScript sources loaded by the page, allowing you to view the content of any script in a formatted viewer.

Technical

Version
1.20.2
Manifest
V3
Size
534KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
emihdlmaomlajmkaanockgjhojehafnp
Developer ID
u7f97f9624f5218d63eddc774b6e350a1
Developer Email
[email protected]
Created
Sep 26, 2025
Last Updated (Store)
Jan 20, 2026
Last Scraped
Jun 8, 2026
Website

Similar extensions

Alternatives to JS Recon Buddy, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified Jun 8, 2026.