Item logo image for DotGit Enhanced

DotGit Enhanced

ExtensionDeveloper Tools17 users
Item media 3 (screenshot) for DotGit Enhanced
Item media 1 (screenshot) for DotGit Enhanced
Item media 2 (screenshot) for DotGit Enhanced
Item media 3 (screenshot) for DotGit Enhanced
Item media 1 (screenshot) for DotGit Enhanced
Item media 1 (screenshot) for DotGit Enhanced
Item media 2 (screenshot) for DotGit Enhanced
Item media 3 (screenshot) for DotGit Enhanced

Overview

Detect exposed .git repositories, download objects, and extract source files — all in one click

DotGit Enhanced is a security research browser extension that automatically detects exposed version control directories and sensitive files on every website you visit. šŸ” WHAT IT DETECTS - Exposed .git/ repositories (validates HEAD content) - .svn/ Subversion databases (SQLite header check) - .hg/ Mercurial repositories (manifest detection) - .env files containing API keys, database credentials, and secrets - .DS_Store macOS metadata files that reveal directory structures - security.txt responsible disclosure policies (RFC 9116) šŸ“¦ ONE-CLICK DOWNLOAD & SOURCE EXTRACTION When an exposed .git repository is found, click the download button to: 1. Fetch Git objects using 50+ well-known paths and dynamic ref discovery 2. Detect directory listings for recursive crawling when available 3. Decompress all Git objects using zlib 4. Traverse commit → tree → blob chains to reconstruct actual source files 5. Deliver a ZIP containing both extracted source code AND raw .git data The resulting ZIP includes: - A source folder with reconstructed files (index.html, config files, scripts, etc.) - A raw .git folder for manual analysis with external tools - An ExtractionReport.txt documenting what was found, extracted, or failed - A DownloadStats.txt with HTTP status code breakdown šŸ›”ļø INTELLIGENCE FEATURES - Open Source Detection — Reads .git/config to identify GitHub/GitLab remotes - security.txt Detection — Finds responsible disclosure contact information - Dynamic Ref Discovery — Scans downloaded files for branch names beyond static lists - Directory Listing Detection — Recursively crawls when server exposes file listings āš™ļø CONFIGURABLE - Toggle detection for each file type independently - Adjustable download concurrency, wait times, and failure thresholds - Hostname blacklist with wildcard support - Desktop notifications for new findings and download progress - Debug mode for troubleshooting šŸŽØ MODERN DARK UI - Stats dashboard with type-based breakdown - Color-coded badges for each finding type - Animated findings list with hover-reveal action buttons - Card-based settings with toggle switches āš ļø IMPORTANT: This tool is designed for authorized security research and educational purposes only. Accessing systems without explicit permission is illegal in most jurisdictions. Always ensure proper authorization before investigating findings. All data is stored locally on your machine — nothing is sent to any external server. Built by Maor D. — Cyber Intelligence Researcher and author of "The Digital Hunter." Based on the original DotGit extension by davtur19, with discovery techniques inspired by git-dumper (Maxime Arthaud) and extraction concepts from GitTools (internetwache). GitHub: https://github.com/MaorDayanOfficial/DotGit-Enhanced

Details

  • Version
    6.0
  • Updated
    March 7, 2026
  • Offered by
    MaorDayan
  • Size
    176KiB
  • Languages
    English
  • Developer
    Email
    maor@maordayan.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

DotGit Enhanced has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

DotGit Enhanced handles the following:

Web history
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps