π Chrome Extension - Detect hardcoded tokens, API keys & secrets in JavaScript files
β50Dec 15, 2025Updated 9 months ago
Alternatives and similar repositories for Hardcoded-Token-Hunter
Users that are interested in Hardcoded-Token-Hunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- π― Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packagesβ41Jan 31, 2026Updated 7 months ago
- Fast Go-based XSS assessment toolkitβ20Mar 18, 2026Updated 6 months ago
- Chrome extension to extract domains from Google search results - by ofjaaahβ20Dec 24, 2025Updated 8 months ago
- SSRFHunterβ18Jan 17, 2026Updated 8 months ago
- Static auditor for randomness and nonce hygiene in Python source - flags weak PRNGs, hardcoded keys, reused counters, static IVs, short sβ¦β25Sep 5, 2026Updated 2 weeks ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- URLess is a simple but powerful tool that removes paths from URLs, generating multiple variations of the base domain. This is useful for β¦β15Apr 1, 2025Updated last year
- Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Codeβ41Apr 1, 2026Updated 5 months ago
- Next-generation intelligent Web Fuzzer & Directory Scanner written in Go. Features WAF detection, secret scanning, auto-calibration, and β¦β26Sep 7, 2026Updated last week
- BountyForge Professional Recon Environment Installerβ16Nov 22, 2025Updated 9 months ago
- Subdomain Enumerator and Simple Crawlerβ453Sep 4, 2026Updated 2 weeks ago
- Smilex-Eye is a high-speed, advanced OSINT suite that bridges the gap between raw global internet data and actionable security intelligenβ¦β34Jun 25, 2026Updated 2 months ago
- Repository aimed at helping to perform pentests on flutter applicationsβ19Jul 10, 2024Updated 2 years ago
- Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personβ¦β153Dec 18, 2025Updated 9 months ago
- Burp Suite extension β passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, entβ¦β55Aug 24, 2026Updated 3 weeks ago
- AI Agents on DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- burpsuite extension to analyze javascript files using semgrepβ13Feb 3, 2025Updated last year
- Rust-powered HTTP Request Smuggling Scanner.β132Aug 30, 2026Updated 2 weeks ago
- Passive JavaScript reconnaissance for penetration testers β bridging Burp Suite traffic into structured, AST-based analysis in VSCode.β36Feb 5, 2026Updated 7 months ago
- A command-line utility for auditing DNS configuration using Zonemaster APIβ34Aug 21, 2023Updated 3 years ago
- A Python script to authenticate and test access to Google Cloud Platform (GCP) resources.β19Jan 31, 2024Updated 2 years ago
- β200Jan 22, 2026Updated 7 months ago
- β264Dec 10, 2025Updated 9 months ago
- React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)β266Dec 12, 2025Updated 9 months ago
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.β50Dec 4, 2025Updated 9 months ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Burp extension to fuzz/brute force GenAI/LLM prompts using a list of various payloads.β36Sep 4, 2025Updated last year
- WebRecon is an advanced Open Source Intelligence (OSINT) web reconnaissance tool designed for cybersecurity professionals, penetration teβ¦β301Mar 20, 2026Updated 5 months ago
- Framework Automatizado de Reconocimiento y ExplotaciΓ³nβ16Mar 8, 2026Updated 6 months ago
- β13Mar 9, 2017Updated 9 years ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information iβ¦β17Apr 13, 2026Updated 5 months ago
- Match & Replace rules for Portswigger's Burp that operate globally across all utilities.β24Jan 26, 2026Updated 7 months ago
- Differential Fuzzer to hunt for logic bugs on Perl Modulesβ26Updated this week
- Burp_Suite-Antigravity_AI-Bug_Bounty_Hunterβ64Feb 9, 2026Updated 7 months ago
- β89May 26, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.β284Aug 12, 2026Updated last month
- β91Sep 13, 2025Updated last year
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.β22Apr 2, 2026Updated 5 months ago
- Generate wordlists using pattern logic and expressions.β23Jun 18, 2026Updated 3 months ago
- one-for-all llm powered, passive & active subdomain enumeration toolβ110Nov 27, 2025Updated 9 months ago
- An Automated Framework for End-to-End Blind XSS Detection and Reportingβ17Jan 23, 2026Updated 7 months ago
- β1,177Jan 28, 2026Updated 7 months ago