Trufflehog-PingPwn
Detects potential exposed secrets on web pages.
As of June 2026, Trufflehog-PingPwn has 1,000 users and a 5.00/5 rating from 1 reviews in the Developer Tools category.
Usersup 52.4 percent+52.4%
1.0K
1,000
Ratingno change0%
5.00
1 reviews
Reviewsno change0%
1
Version
0.0.4
Manifest V3
History
6 snapshotsTracking since Apr 1, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 1, 2026 | 656 | — | — | 0.0.4 |
| Apr 18, 2026 | 679 | — | — | 0.0.4 |
| Apr 28, 2026 | 790 | — | — | 0.0.4 |
| May 8, 2026 | 844 | — | — | 0.0.4 |
| May 15, 2026 | 889 | — | — | 0.0.4 |
| May 24, 2026 | 943 | 5.00 | 1 | 0.0.4 |
| Now | 1.0K | 5.00 | 1 | 0.0.4 |
Permissions & access
- Permissions
- activeTabtabsstoragenotifications
- Host access
- https://*/*, http://*/*
Screenshots
About
Trufflehog-PingPwn scans web pages and referenced resources for common secret patterns (API keys, tokens, private keys, webhook URLs) so you can identify accidental exposures quickly. Scanning and detection are performed entirely in your browser; this extension does not send findings to any remote server. Use the popup to review findings, clear them, or download a CSV of results. This extension tries to brings the scanning & Detection capabilities of well known Trufflehog to browser in real time scanning. Key features: - Detects generic API keys, specific provider tokens, and common secret formats. - Optionally checks for `.env` files and `.git` directories (may trigger server protections). - Shows per-origin findings with a badge count and in-popup listing. - Local-only storage of findings using the browser's storage; no remote transmission. Core Detection Features: - Detects API keys, tokens, private keys, and webhook URLs on web pages - Scans referenced resources (external scripts, .env files, .git directories) - Recognizes patterns from 30+ secret providers. - Supports generic secret patterns (API keys, database credentials, passwords) - Base64-encoded secret detection with automatic decoding - Real-time scanning as you browse UI & User Experience: - Clean, intuitive popup interface with toggle controls - Badge count on toolbar showing findings per origin - Per-origin findings list with detailed match information - One-click clearing of findings (current origin or all) - CSV export for audit trails and compliance reporting - Origin-based filtering and deny list to skip specific domains - Local notification alerts for critical findings (e.g., .git directories) - Customizable detection rule toggles (turn on/off specific categories) Privacy statement: All scanning and analysis occurs locally inside the browser. No findings, page contents, or extracted secrets are transmitted to external servers. The extension uses `chrome.storage.sync` to store settings and detected findings on your browser; you can clear stored findings via the popup. Developer contact: [email protected] Keywords: secrets, security, trufflehog, scan, credentials, api-keys, bugbounty, security, scanning, bug-bounty, developer-tools, exposure-detection, penetration-testing
Technical
- Version
- 0.0.4
- Manifest
- V3
- Size
- 39.07KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- ojpilaklfjcfpehafidhijapphckbbbo
- Developer ID
- ube585a9e733622acc1f8f25216c33bee
- Developer Email
- [email protected]
- Created
- Dec 26, 2025
- Last Updated (Store)
- Dec 30, 2025
- Last Scraped
- Jun 3, 2026
- Website
- —
Similar extensions
Alternatives to Trufflehog-PingPwn, ranked by description similarity.
AppSec Inspector
Professional security inspection tool. Scan headers, detect secrets, audit auth - all locally, no data collection.
6
ClawSentinel Guard
Detects hidden prompt injection on webpages. Protects your AI agent from being hijacked by malicious content.
—
PRISM
PRISM - Advanced browser-based secret scanner that reveals invisible security risks. Refracting the web to find hidden secrets.
5
Clip Guard AI
Automatically detect and mask API keys, tokens, and secrets when pasting to AI chatbots
3
Aegis OmniGuard
Scans input locally for credit cards, API keys & crypto mnemonics before sending to AI chatbots. 100% offline, open source.
7
How Fugu is the Web?
An extension to shine light on the Project Fugu 🐡 APIs web apps want to use.
48
SecuriScan - Web Security Analyzer
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
327
OWASP Penetration Testing Kit
OWASP Penetration Testing Kit
20.0K
★ 4.8
Data sourced from the Chrome Web Store · last verified Jun 3, 2026.