Item logo image for API Call Detector

API Call Detector

Item media 2 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 2 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 2 (screenshot) for API Call Detector

Overview

Security tool to actively detect external API calls made from displayed web page

API Call Detector - Cybersecurity Analysis Tool Identify potential security risks by mapping all external API calls made through JavaScript. This professional-grade extension provides real-time monitoring of web page communications, helping security teams uncover hidden data flows, unauthorized third-party integrations, and potential attack vectors. Key Features: Real-time detection of XMLHttpRequest, Fetch API, and WebSocket connections Automatic filtering of static resources (images/CSS/fonts) Security-focused reporting with domain frequency analysis Exportable audit trails in markdown format Cross-origin call tracking with full URL capture Manifest V3 compliant with strict CSP policies Ideal For: Identifying shadow APIs in enterprise web applications Auditing data flows for GDPR/HIPAA compliance Detecting unauthorized third-party trackers Educational white-hat hacking exercises Penetration testing reconnaissance phases Monitoring client-side supply chain risks Technical Specifications: Operates at document_start phase to capture initializations Content script injection via Chrome extension APIs Background service worker maintains isolated call registry Secure message passing between components Zero data collection/telemetry Use Cases: Vulnerability Assessment: Map all external endpoints contacted during user sessions Incident Response: Quickly identify compromised APIs during breach investigations Third-Party Audit: Document data leakage points to external services Developer Education: Visualize runtime network behavior of SPAs Compliance Reporting: Generate evidence of endpoint security checks Advanced Capabilities: Path-based sorting and domain clustering Automatic deduplication of repeated calls Query parameter stripping for clean analysis Multi-frame tracking (iframes/web workers) Detection bypass prevention through prototype hooks For Security Teams: Prioritize endpoints by call frequency Spot anomalous domains in real-time Export findings to standard threat intelligence formats Integrate with SIEM systems via manual export Development Philosophy: Minimal permissions required (storage, downloads, webNavigation) No background page persistence Strict content security policy enforcement Regular updates to match evolving web standards Open Source Ready: Clean codebase for organizational customization MIT License (contact developer for enterprise terms) Built for extensibility (add custom filters/hooks) Install to gain immediate visibility into client-side network activity and strengthen your organization's web application security posture. Essential for modern cybersecurity defense-in-depth strategies.

5 out of 51 rating

Google doesn't verify reviews. Learn more about results and reviews.

Details

  • Version
    1.0
  • Updated
    March 18, 2025
  • Size
    53.75KiB
  • Languages
    English
  • Developer
    Geekus Maximus
    39 N Main St New Castle, KY 40050 US
    Website
    Email
    docdaven@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

Copy Element Data

5.0(1)

Let you copy element name / id more easily.

Pentest Assistant

5.0(3)

Checklist dan Mindmap untuk membantu pentester dan bug hunter.

Get That API

5.0(2)

Get That API is an browser extension made to test API endpoints right in the browser

Hidden APIs

0.0(0)

Find & inspect internal APIs, scrape & automate tasks with ease. Ideal for devs, data scientists & web enthusiasts.

DIRFOX - Endpoint Fuzzer for Pentesters

0.0(0)

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Pentest Recon+

5.0(1)

A comprehensive penetration testing reconnaissance tool.

Detector APIs Extension

5.0(3)

The extension supports getting all APIs and CURL command when load a website.

Bolt

5.0(2)

The purpose of this Google Chrome extension is to provide support to pentesters and developers in testing web applications

API Response Viewer

0.0(0)

Captures, formats, and displays API responses in a clean interface for easy debugging and analysis of web applications.

Vueable Query

5.0(7)

This extension creates a Dev Tool Panel to monitor performance metrics for Vue apps that use Tanstack Query for Vue.

Subdomain Finder - Find Hidden Subdomains

0.0(0)

The best Subdomain Finder tool for bug bounty hunters and security researchers. Find hidden subdomains quickly and easily.

PageTree Inspector

1.0(1)

Visualize distribution of DOM nodes in the document tree

Copy Element Data

5.0(1)

Let you copy element name / id more easily.

Pentest Assistant

5.0(3)

Checklist dan Mindmap untuk membantu pentester dan bug hunter.

Get That API

5.0(2)

Get That API is an browser extension made to test API endpoints right in the browser

Hidden APIs

0.0(0)

Find & inspect internal APIs, scrape & automate tasks with ease. Ideal for devs, data scientists & web enthusiasts.

DIRFOX - Endpoint Fuzzer for Pentesters

0.0(0)

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Pentest Recon+

5.0(1)

A comprehensive penetration testing reconnaissance tool.

Detector APIs Extension

5.0(3)

The extension supports getting all APIs and CURL command when load a website.

Bolt

5.0(2)

The purpose of this Google Chrome extension is to provide support to pentesters and developers in testing web applications

Google apps