JS Recon & Secret Scanner

Inspect JavaScript files locally to find likely endpoints, possible secret-like strings, and available sourcemaps.

As of June 2026, JS Recon & Secret Scanner has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
2.1.0
Manifest V3

History

1 snapshots

Tracking since Jun 24, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
Jun 24, 20262.1.0
Now2.1.0

Permissions & access

Permissions
activeTabscripting
Host access
None declared

Screenshots

JS Recon & Secret Scanner screenshot 1

About

JS Recon & Secret Scanner is a powerful, privacy-first Manifest V3 Chrome extension designed for developers, security researchers, and authorized penetration testers. It allows you to inspect JavaScript files loaded by the current active page to easily identify likely endpoints, possible secret-like strings, and available sourcemaps.

Unlike other scanning tools, this extension processes everything locally in your browser. It does not use external backend servers, tracking scripts, or analytics.

🛡️ CORE FEATURES:
• User-Initiated Scanning: The extension only runs when you actively click "Scan Current Page". Zero background drain.
• Endpoint Discovery: Extracts likely API routes, internal paths, form endpoints, GraphQL paths, and versioned APIs from JS bundles.
• Smart Categorization: Automatically groups findings into App Endpoints, Tracking/Analytics, Media Embeds, and Consent/Privacy to filter out the noise.
• Secret & Token Detection: Uses regex patterns to identify exposed API keys, JWTs, and tokens, complete with confidence labels and safe-masking UI.
• Sourcemap Probing: Checks if related `.js.map` files are exposed on the host.
• Memory-Safe Parsing: Uses streamed fetching and file-size caps to prevent browser crashes on massive Webpack/React bundles.

🔐 STRICT PRIVACY:
Your data never leaves your browser. 
• No data is sent to the developer.
• No analytics or tracking pixels.
• No remote logging.
• Uses minimal permissions (`activeTab` and `scripting`). Optional cross-origin permissions are only requested if you manually choose to scan third-party scripts.

⚠️ RESPONSIBLE USE:
This tool is intended for defensive security review, development debugging, and authorized testing only. Users are responsible for following all applicable laws, website terms of service, and bug bounty rules. Use this extension only on websites that you own, manage, or are explicitly authorized to test.

Technical

Version
2.1.0
Manifest
V3
Size
45.94KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
gmompfcmnhnldbpofnnamlcekholkfnh
Developer ID
u0c8649e41e5f3ebc2def039f369cd733
Developer Email
[email protected]
Created
Jun 23, 2026
Last Updated (Store)
Jun 23, 2026
Last Scraped
Jun 24, 2026
Website

Data sourced from the Chrome Web Store · last verified Jun 24, 2026.