Item logo image for DotDrop - Sensitive File Detector

DotDrop - Sensitive File Detector

Item media 1 (screenshot) for DotDrop - Sensitive File Detector

Overview

Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.

# DotDrop - Sensitive File Detector Automatically scan websites for exposed sensitive files and security vulnerabilities. Perfect for security researchers, developers, and bug bounty hunters. ## šŸ” What It Detects DotDrop scans for 80+ types of exposed files including: - **Version Control**: .git/, .svn/, .hg/ - **Credentials**: .env, .htpasswd, SSH keys (id_rsa) - **Cloud Keys**: AWS, GCP, Azure credentials - **Database Files**: SQL dumps, MongoDB backups - **Configuration**: Docker, Kubernetes, CI/CD configs - **Backups**: ZIP, TAR, SQL backup files ## ✨ Key Features - **Traffic Light System**: 🟢 Safe / 🟠 Not Scanned / šŸ”“ Vulnerable - **Real-time Scan Progress**: See exactly what's being checked - **One-Click Copy**: Export findings as formatted Markdown reports - **Detection Age Tracking**: "2h ago", "3d ago" timestamps - **Stealth Mode**: Slower scanning to avoid rate limiting - **Batch Scanning**: Test multiple domains at once - **Export Options**: JSON, CSV, or Markdown formats - **Statistics Dashboard**: Track vulnerable sites and severity breakdown - **100% Local**: Zero data collection, complete privacy ## šŸ”’ Privacy & Security āœ… All processing happens locally on your device āœ… No data sent to external servers āœ… No analytics or tracking āœ… Open source - inspect the code yourself āœ… Minimal permissions (only what's needed) ## šŸŽÆ Perfect For - Security researchers conducting vulnerability assessments - Developers checking their own sites for exposed files - Bug bounty hunters finding security issues - DevOps teams auditing infrastructure - Anyone concerned about web security ## šŸš€ How It Works 1. Browse normally - DotDrop scans automatically 2. Check the icon - Color indicates security status 3. Click to view - See detailed findings 4. Export results - Copy or download reports ## šŸ›”ļø False Positive Prevention Advanced 5-layer validation system ensures accurate detection: - HTTP 200 status verification - Content-Type checking - File size validation - HTML error page detection - Content pattern analysis ## šŸ“Š Professional Features - **Severity Levels**: Critical, Medium, Low color-coded alerts - **Pattern Groups**: Enable/disable specific detection categories - **Detection History**: Track all findings over time - **Customizable Settings**: Auto-scan, critical-only mode - **Badge Counter**: Shows number of exposed files found ## 🌐 Use Cases **For Developers:** Test your own websites before deployment to catch exposed configuration files, credentials, or backup files that shouldn't be public. **For Security Researchers:** Quickly identify common security misconfigurations during reconnaissance. Export findings for professional reports. **For Bug Bounty Hunters:** Automate the detection of low-hanging fruit vulnerabilities. Copy findings directly to bug reports with one click. ## ⚔ Lightweight & Fast - Minimal resource usage - Fast parallel scanning - Clean, professional UI - No bloat or unnecessary features ## šŸ”§ Technical Details - Manifest V3 compliant - Works on all HTTP/HTTPS sites - Respects browser security policies --- **Disclaimer**: This tool is for ethical security research and educational purposes only. Always obtain proper authorization before testing websites you don't own.

Details

  • Version
    1.1.0
  • Updated
    November 4, 2025
  • Offered by
    Interzone
  • Size
    26.78KiB
  • Languages
    English
  • Developer
    Email
    interzoneart01@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

Extension Auditor Pro - Assess Risk & Improve Browser Security Posture

5.0

Assess, and monitor browser extensions for security and privacy risks. Improve your Browser Security Posture and Stay Safe Oonline.

ZeroThreat AI Recorder – Most Intelligent DAST Tool

4.7

Automate threat & vulnerability detection (OWASP Top 10) for web apps & APIs. Fits developers & pentesters.

PageShield

5.0

Detects hidden elements (buttons and windows) on websites and blocks trackers.

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

RemindSecure Anti-Phishing

5.0

All-in-one security: Set reminders, prevent phishing, manage passwords, and browse safely with expert guidance.

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

PENGUARDS: Abstract Session keys Security Manager

0.0

Review Abstract session keys, monitor risk signals, and revoke access directly from the browser.

Feroot PageScanner

5.0

Feroot PageScanner enables you to perform privacy and security compliance assessments (PCI-DSS 4.0, HIPAA, CCPA)

Site Inspector

4.8

Inspect. Analyze. Understand. All-in-one tool for web developers and SEO professionals. Comprehensive web analysis and insights.

Sourdough - ServiceNow Monitoring and Analytics

4.4

A Chrome extension for ServiceNow Admins and Developers with essential tools, analytics, graphs and monitoring features.

Online AntiVirus Protection

2.9

Online URL scan through context menu, file scan through webapp and malware protection through safe search.

LambdaTest Accessibility DevTools

4.9

LambdaTest Accessibility DevTools - The Go-to Accessibility Auditor for Developers, Testers, and Product Managers.

Extension Auditor Pro - Assess Risk & Improve Browser Security Posture

5.0

Assess, and monitor browser extensions for security and privacy risks. Improve your Browser Security Posture and Stay Safe Oonline.

ZeroThreat AI Recorder – Most Intelligent DAST Tool

4.7

Automate threat & vulnerability detection (OWASP Top 10) for web apps & APIs. Fits developers & pentesters.

PageShield

5.0

Detects hidden elements (buttons and windows) on websites and blocks trackers.

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

RemindSecure Anti-Phishing

5.0

All-in-one security: Set reminders, prevent phishing, manage passwords, and browse safely with expert guidance.

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

PENGUARDS: Abstract Session keys Security Manager

0.0

Review Abstract session keys, monitor risk signals, and revoke access directly from the browser.

Feroot PageScanner

5.0

Feroot PageScanner enables you to perform privacy and security compliance assessments (PCI-DSS 4.0, HIPAA, CCPA)

Google apps