DotDrop - Sensitive File Detector
Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.
As of June 2026, DotDrop - Sensitive File Detector has 35 users in the Developer Tools category.
Usersup 29.6 percent+29.6%
35
35
Ratingno change0%
—
— reviews
Reviewsno change0%
—
Version
1.1.0
Manifest V3
History
5 snapshotsTracking since Apr 18, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 18, 2026 | 27 | — | — | 1.1.0 |
| Apr 27, 2026 | 25 | — | — | 1.1.0 |
| May 7, 2026 | 28 | — | — | 1.1.0 |
| May 19, 2026 | 31 | — | — | 1.1.0 |
| Jun 2, 2026 | 37 | — | — | 1.1.0 |
| Now | 35 | — | — | 1.1.0 |
Permissions & access
- Permissions
- storageactiveTab
- Host access
- <all_urls>
Screenshots
About
# DotDrop - Sensitive File Detector Automatically scan websites for exposed sensitive files and security vulnerabilities. Perfect for security researchers, developers, and bug bounty hunters. ## 🔍 What It Detects DotDrop scans for 80+ types of exposed files including: - **Version Control**: .git/, .svn/, .hg/ - **Credentials**: .env, .htpasswd, SSH keys (id_rsa) - **Cloud Keys**: AWS, GCP, Azure credentials - **Database Files**: SQL dumps, MongoDB backups - **Configuration**: Docker, Kubernetes, CI/CD configs - **Backups**: ZIP, TAR, SQL backup files ## ✨ Key Features - **Traffic Light System**: 🟢 Safe / 🟠 Not Scanned / 🔴 Vulnerable - **Real-time Scan Progress**: See exactly what's being checked - **One-Click Copy**: Export findings as formatted Markdown reports - **Detection Age Tracking**: "2h ago", "3d ago" timestamps - **Stealth Mode**: Slower scanning to avoid rate limiting - **Batch Scanning**: Test multiple domains at once - **Export Options**: JSON, CSV, or Markdown formats - **Statistics Dashboard**: Track vulnerable sites and severity breakdown - **100% Local**: Zero data collection, complete privacy ## 🔒 Privacy & Security ✅ All processing happens locally on your device ✅ No data sent to external servers ✅ No analytics or tracking ✅ Open source - inspect the code yourself ✅ Minimal permissions (only what's needed) ## 🎯 Perfect For - Security researchers conducting vulnerability assessments - Developers checking their own sites for exposed files - Bug bounty hunters finding security issues - DevOps teams auditing infrastructure - Anyone concerned about web security ## 🚀 How It Works 1. Browse normally - DotDrop scans automatically 2. Check the icon - Color indicates security status 3. Click to view - See detailed findings 4. Export results - Copy or download reports ## 🛡️ False Positive Prevention Advanced 5-layer validation system ensures accurate detection: - HTTP 200 status verification - Content-Type checking - File size validation - HTML error page detection - Content pattern analysis ## 📊 Professional Features - **Severity Levels**: Critical, Medium, Low color-coded alerts - **Pattern Groups**: Enable/disable specific detection categories - **Detection History**: Track all findings over time - **Customizable Settings**: Auto-scan, critical-only mode - **Badge Counter**: Shows number of exposed files found ## 🌐 Use Cases **For Developers:** Test your own websites before deployment to catch exposed configuration files, credentials, or backup files that shouldn't be public. **For Security Researchers:** Quickly identify common security misconfigurations during reconnaissance. Export findings for professional reports. **For Bug Bounty Hunters:** Automate the detection of low-hanging fruit vulnerabilities. Copy findings directly to bug reports with one click. ## ⚡ Lightweight & Fast - Minimal resource usage - Fast parallel scanning - Clean, professional UI - No bloat or unnecessary features ## 🔧 Technical Details - Manifest V3 compliant - Works on all HTTP/HTTPS sites - Respects browser security policies --- **Disclaimer**: This tool is for ethical security research and educational purposes only. Always obtain proper authorization before testing websites you don't own.
Technical
- Version
- 1.1.0
- Manifest
- V3
- Size
- 26.78KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- oeknaicglkafmhokkehnflfaomjgflgo
- Developer ID
- u90af7687dbcf5c277f0e5fb18ef14fbc
- Developer Email
- [email protected]
- Created
- Nov 4, 2025
- Last Updated (Store)
- Nov 4, 2025
- Last Scraped
- Jun 2, 2026
- Website
- —
- Support URL
- —
- Privacy Policy
- https://github.com/rafabez/dotdrop
Similar extensions
Alternatives to DotDrop - Sensitive File Detector, ranked by description similarity.
DotGit Enhanced
Detect exposed .git repositories, download objects, and extract source files — all in one click
51
SecuriScan - Web Security Analyzer
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
327
IsItExposed
Scans sites for exposed files, open directories, and web vulnerabilities. Built for devs, teams, and security-conscious owners
19
AppSec Inspector
Professional security inspection tool. Scan headers, detect secrets, audit auth - all locally, no data collection.
6
PRISM
PRISM - Advanced browser-based secret scanner that reveals invisible security risks. Refracting the web to find hidden secrets.
5
VaptFinder: Vulnerability & Library Detector
Inspects websites for outdated libraries and checks browser vulnerability.
64
SQL Injection Checker
Professional security testing tool for detecting SQL injection vulnerabilities
159
★ 5.0
DetectZeStack — Website Tech Stack Detector
Detect any website's tech stack instantly. Finds frameworks, CDNs, analytics via DNS, TLS, and HTTP — no injection.
14
Data sourced from the Chrome Web Store · last verified Jun 2, 2026.