Frontguard by Pubflow

Friendly client-side security audits for modern web apps.

As of June 2026, Frontguard by Pubflow has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.1.0
Manifest V3

History

1 snapshots

Tracking since May 17, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
May 17, 20260.1.0
Now0.1.0

Permissions & access

Permissions
activeTabscriptingstorage
Host access
None declared

Screenshots

Frontguard by Pubflow screenshot 1

About

Frontguard is a local-first client-side security scanner for modern web apps. It helps developers review browser-visible risks before they become production incidents.

Use Frontguard to scan the current tab for exposed secrets, public frontend environment variables, risky client-side storage, security header gaps, framework signals, BaaS/auth configuration, and suspicious network behavior.

Frontguard supports safe passive scans and opt-in deep active scans. Safe scans inspect loaded assets, storage, visible cookies, headers, and resource signals without replaying requests or modifying data. Deep active scans only start when you explicitly enable them, then locally observe fetch/XHR traffic while you use the app.

What Frontguard can help detect:

Exposed API keys and secret-like values:
Supabase, Firebase, Clerk, Auth0, Cognito, Appwrite, Hasura, Sanity, and Contentful client-side signals
Stripe publishable vs secret key exposure
Public frontend env variables such as VITE_*, NEXT_PUBLIC_*, PUBLIC_*, REACT_APP_*, and more
Sensitive data in browser storage
Request/response patterns that may expose auth, billing, tenant, role, or user data
GraphQL and introspection signals
Missing or weak security headers such as CSP, HSTS, Referrer-Policy, Permissions-Policy, and CORS
IndexedDB and Cache Storage persistence signals
Framework signals for Vite, React, Next.js, Nuxt, SvelteKit, Astro, Angular, and others
Frontguard is designed to be friendly, defensive, and non-invasive. It does not brute force, replay requests, submit forms, mutate data, or upload scan evidence. Results stay local in your browser, and sensitive values are masked by default.

Built by Pubflow for developers who want clearer client-side security reviews without vendor lock-in.

Technical

Version
0.1.0
Manifest
V3
Size
199KiB
Min Chrome
114
Languages
1
Featured
No

Metadata

ID
nmcnpleafkgfloinaeknfnbdmcnlfgin
Developer ID
u949a3458d7b7bacd7e57df88c458274c
Developer Email
[email protected]
Created
May 16, 2026
Last Updated (Store)
May 16, 2026
Last Scraped
Jun 13, 2026
Website
pubflow.com
Support URL

Data sourced from the Chrome Web Store · last verified Jun 13, 2026.