Orion Open Redirect Hunter

Automated, safe scanner for Open Redirect vulnerabilities. Does not follow redirects; records Location/meta/JS evidence.

As of May 2026, Orion Open Redirect Hunter has 19 users in the Developer Tools category.

Usersup 26.7 percent+26.7%
19
19
Ratingno change0%
— reviews
Reviewsno change0%
Version
1.0.0
Manifest V3

History

4 snapshots

Tracking since Apr 1, 2026.

22.5618.514.44Apr 1, 2026May 30, 2026
View as table
DateUsersRatingReviewsVersion
Apr 1, 2026151.0.0
Apr 20, 2026161.0.0
May 5, 2026151.0.0
May 30, 2026221.0.0
Now191.0.0

Permissions & access

Permissions
storagewebRequest
Host access
<all_urls>

Screenshots

Orion Open Redirect Hunter screenshot 1Orion Open Redirect Hunter screenshot 2Orion Open Redirect Hunter screenshot 3

About

Orion Open Redirect Hunter automates manual tests for Open Redirect (Unvalidated Redirects/Forwards) in web apps.
It injects benign, controlled payloads pointing to example.com and never follows redirects. Instead, it observes:

HTTP 3xx Location headers

HTML meta refresh tags

JavaScript redirects (location.href, location.assign, location.replace)

If a redirect to the canary destination is detected, the tool flags the URL as vulnerable and records clear evidence.

Why it’s safe
No redirect following: requests are issued with redirect handling disabled

Benign payloads only (https://example.com, //example.com, and encoded variants)

Timeouts & optional rate limiting to avoid stressing targets

No third-party services: everything runs locally in your browser

Key features
Test one or many URLs (paste multiple; one per line)

Auto-detect common redirect parameters (next, redirect_uri, returnTo, etc.) or specify your own

Choose GET or HEAD, set timeout and delay between requests

View results inline and Export JSON with full evidence (status, header, mechanism)

Clear legal/ethical banner; intended for authorized testing only

Typical use cases
Security reviews of login flows, OAuth/OIDC callbacks, and post-login redirect chains

AppSec CI/spot checks during release hardening

Bug bounty triage and validation

How it works (high level)
You paste URLs to scan

The tool sets candidate redirect parameters to benign URLs (and encoded variants)

It sends requests with redirect=manual and inspects response headers and HTML

Findings are displayed and can be exported as JSON

Notes
Only test systems you own or have permission to assess

You may need to whitelist targets in your testing scope and follow responsible disclosure practices

open redirect, unvalidated redirect, redirect_uri, OAuth, OIDC, AppSec, bug bounty, security testing, Location header, meta refresh, JavaScript redirect, penetration testing (authorized)

Technical

Version
1.0.0
Manifest
V3
Size
218KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
nhidgdjfenjgfkebimhdanbfipgfacpl
Developer ID
uf36c2120deeb9fabce3b7781118d64e4
Developer Email
[email protected]
Created
Aug 13, 2025
Last Updated (Store)
Aug 13, 2025
Last Scraped
May 30, 2026
Website
Support URL

Similar extensions

Alternatives to Orion Open Redirect Hunter, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified May 30, 2026.