jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.
☆538Sep 20, 2026Updated this week
Alternatives and similar repositories for JShunter
Users that are interested in JShunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆61Feb 22, 2025Updated last year
- A passive way to find backups/ sensitive information.☆95Jul 10, 2025Updated last year
- High-Performance JavaScript Security Scanner - Process 1M URLs in ~5 hours with Telegram & Discord bot integration, Docker support, and c…☆176Oct 18, 2025Updated 11 months ago
- ParamScan is a chrome extension for finding reflected parameters in a webpage.☆92Jan 11, 2025Updated last year
- best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect☆1,619Dec 7, 2025Updated 9 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,881Jun 21, 2026Updated 3 months ago
- A high-performance Go-based tool for checking the availability and responsiveness of domains, utilizing both HTTP requests and browser au…☆92Nov 26, 2024Updated last year
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆567Mar 8, 2025Updated last year
- Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets☆150Jan 21, 2025Updated last year
- A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.☆913Sep 14, 2026Updated last week
- Header Exploitation HTTP☆762Sep 6, 2026Updated 2 weeks ago
- An IIS short filename enumeration tool☆1,222Nov 25, 2024Updated last year
- Orbis is an full spectrum automated external attack surface intelligent toolkit.☆412Aug 12, 2026Updated last month
- SubOwner - A Simple tool check for subdomain takeovers.☆122Oct 18, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A rapid HTTP downgrade smuggling scanner written in Go.☆312May 16, 2024Updated 2 years ago
- Automation tool to testing and confirm the xss vulnerability.☆306Jul 18, 2025Updated last year
- Zzl is a reconnaissance tool that collects subdomains from SSL certificates in IP ranges☆43Oct 27, 2024Updated last year
- Automatic SSTI detection tool with interactive interface☆1,643Aug 25, 2026Updated 3 weeks ago
- A simple browser extension to quickly find interesting security-related information on a webpage.☆189Sep 11, 2026Updated 2 weeks ago
- An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws☆4,078Oct 4, 2025Updated 11 months ago
- NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Re…☆1,865Apr 17, 2026Updated 5 months ago
- ☆1,177Jan 28, 2026Updated 7 months ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers☆310Mar 31, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter☆3,644Feb 10, 2024Updated 2 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆876Sep 12, 2026Updated last week
- ☆91Sep 13, 2025Updated last year
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!☆2,752Jun 11, 2026Updated 3 months ago
- Pen Hunter is a comprehensive vulnerability scanning tool designed for penetration testers, security researchers and bug bounties. it aut…☆30Jul 12, 2026Updated 2 months ago
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆31Jun 13, 2025Updated last year
- Automate Recon XSS Bug Bounty☆192Mar 9, 2026Updated 6 months ago
- declutters url lists for crawling/pentesting☆1,594Feb 23, 2025Updated last year
- Robofinder fetches historical robots.txt files from Archive.org to uncover old directories, hidden paths, and valuable OSINT data for rec…☆273Jun 13, 2026Updated 3 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆547Aug 21, 2025Updated last year
- List of Directory Traversal/LFI Payloads Scraped from the Internet☆184Feb 10, 2025Updated last year
- AI-powered ffuf wrapper☆806Dec 4, 2025Updated 9 months ago
- All-in Fuzzer. Burp suite extension for auto fuzzing params, headers, body☆36Apr 9, 2026Updated 5 months ago
- Top disclosed reports from HackerOne☆6,560Sep 12, 2026Updated last week
- IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applicatio…☆235Sep 25, 2025Updated 11 months ago
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty☆807Jun 21, 2026Updated 3 months ago