SecuriScan - Web Security Analyzer
Overview
Lightweight security scanner that analyzes websites for common vulnerabilities, trackers, and security misconfigurations
SecuriScan is a powerful Chrome extension that performs comprehensive passive security analysis on any website. Built for developers, security professionals, and anyone who wants quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. ๐ ๐ช๐๐๐ง'๐ฆ ๐ก๐๐ช ๐๐ก ๐ฉ๐ญ.๐ฐ.๐ฌ โข ๐ก OWASP Top 10 view โ maps every finding to the OWASP Top 10 (2021) with PASS/WARN/FAIL badges โข ๐ค AI Explain & Fix โ one-click explanations and copy-paste code fixes for every vulnerability found โข ๐ Side Panel mode โ persistent scanning panel that stays open alongside your browsing (Alt+Shift+P) โข ๐ข Toolbar badge โ live issue count on the extension icon, colour-coded by severity โข ๐ก Network security scan โ detects insecure WebSockets (ws://), WebRTC IP leakage, unsafe postMessage usage, hardcoded private IPs, and dynamic script injection โข โ SARIF 2.1.0 export โ export results in industry-standard SARIF format for CI/CD pipeline integration โข โจ Keyboard shortcuts โ Alt+Shift+S to scan, Alt+Shift+P to open the side panel โข ๐ฑ Right-click context menu โ scan any page directly from the right-click menu โข โ Settings tab โ toggle auto-scan (opt-in, off by default), desktop notifications, and badge display โข ๐ Score sparklines โ visual score history chart per domain in the History tab ๐ ๐ช๐๐๐ง'๐ฆ ๐ก๐๐ช ๐๐ก ๐ฉ๐ญ.๐ฏ.๐ฌ โข ๐ Privacy tracker detection โ flags 18 third-party trackers including Meta Pixel, TikTok, Hotjar, FullStory, and more โข ๐พ Browser storage audit โ scans localStorage and sessionStorage for exposed tokens, keys, and PII โข ๐ Scan history & score trends โ tracks your last 10 scans per domain and shows โ/โ trend on every result โข ๐ JSON export โ export results as machine-readable JSON alongside the existing HTML report ๐ ๐ช๐๐๐ง ๐๐ง ๐๐ข๐๐ฆ When you click scan, SecuriScan analyzes the current page for security misconfigurations and vulnerabilities across 13 categories: ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฒ๐ฎ๐ฑ๐ฒ๐ฟ๐ (๐ญ๐ฌ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐) โข Content-Security-Policy (CSP) โข Strict-Transport-Security (HSTS) โข X-Frame-Options โข X-Content-Type-Options โข Referrer-Policy โข Permissions-Policy โข Cross-Origin-Opener-Policy โข Cross-Origin-Resource-Policy โข Cross-Origin-Embedder-Policy โข X-XSS-Protection ๐ช ๐๐ผ๐ผ๐ธ๐ถ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ โข HttpOnly and Secure flag validation โข Session token exposure detection โข Sensitive cookie pattern matching โข SameSite attribute guidance ๐ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ ๐๐ฎ๐๐ฎ๐ฆ๐ฐ๐ฟ๐ถ๐ฝ๐ ๐๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐ (๐ฏ๐ฑ+ ๐น๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐) ๐ด Critical Severity: โข Handlebars < 4.7.7 (arbitrary code execution) โข Socket.IO < 4.4.1 (CORS bypass) โข Minimist < 1.2.6 (prototype pollution) โข EJS < 3.1.7 (template injection) ๐ High Severity: โข jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) โข AngularJS < 1.8.3 (CVE-2023-26116) โข Lodash < 4.17.21 (CVE-2021-23337, CVE-2020-28500) โข React < 16.14.0 (CVE-2021-23648) โข Vue.js < 2.6.14 (CVE-2021-3766) โข Marked < 4.0.10 (ReDoS and XSS) โข DOMPurify < 2.3.10 (XSS bypass) โข Express < 4.17.3 (open redirect) โข Webpack < 5.76.0 (cross-realm access) โข Underscore < 1.13.0 (code execution) โข Next.js < 12.3.2 (open redirect) โข Nuxt.js < 2.15.7 (directory traversal) โข Pug < 3.0.1 (code injection) ๐ก Medium Severity: โข Bootstrap < 4.3.1 (CVE-2019-8331) โข Moment.js < 2.29.4 (CVE-2022-31129) โข Axios < 0.21.3 (SSRF) โข D3.js, Chart.js, DataTables, and more ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐๐ฎ๐๐ฎ ๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ (๐ฎ๐ฑ+ ๐ฝ๐ฎ๐๐๐ฒ๐ฟ๐ป๐) ๐ API Keys & Tokens: โข AWS Access/Secret Keys โข Google API Keys & OAuth โข GitHub Personal Access Tokens โข Stripe API Keys (live & test) โข Slack Tokens โข Twilio, SendGrid, Mailgun API Keys โข PayPal Braintree Tokens โข Square OAuth Secrets โข Shopify Access Tokens & Shared Secrets โข Generic API key patterns ๐ Credentials & Secrets: โข Private Keys (RSA, SSH, EC, PGP, OpenSSH) โข Database Connection Strings (MongoDB, MySQL, PostgreSQL) โข JWT Tokens โข Passwords in source code โข Firebase URLs ๐ชช PII: โข Credit Card Patterns โข Social Security Numbers โข Email Addresses (filtered for false positives) ๐ ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐ง๐ฟ๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ Detects 18 third-party tracking scripts that collect and share your users' behavioral data: โข ๐ฅ Session recorders: Hotjar, FullStory, Mouseflow, Crazy Egg โข ๐ข Ad pixels: Meta/Facebook, TikTok, Twitter/X, LinkedIn Insight โข ๐ Analytics: Google Analytics, Google Tag Manager, Mixpanel, Amplitude, Heap, Clarity โข ๐ฌ CRM: HubSpot, Intercom, Pardot, Segment Each tracker is rated by severity โ session recorders (high) vs. analytics-only (medium) โ so you know which ones are most invasive. ๐พ ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ ๐ฆ๐๐ผ๐ฟ๐ฎ๐ด๐ฒ ๐๐๐ฑ๐ถ๐ Scans localStorage and sessionStorage for sensitive data that XSS could steal: โข Auth tokens, JWT, session IDs stored under sensitive key names โข API keys, AWS credentials, private keys in stored values โข Credit card numbers and SSNs โข Flags risky storage patterns and recommends HttpOnly cookies instead ๐ก ๐ก๐ฒ๐๐๐ผ๐ฟ๐ธ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ (๐ก๐๐ช ๐ถ๐ป ๐๐ญ.๐ฐ.๐ฌ) Passively inspects inline scripts for risky network patterns: โข Insecure WebSocket connections using ws:// instead of wss:// โข WebRTC usage that can leak real IP addresses through VPNs โข postMessage() calls without event.origin validation โข Hardcoded private/internal IP addresses (192.168.x, 10.x, 127.0.0.1) โข Dynamic <script> element injection โข Hardcoded cross-origin fetch endpoints โ ๏ธ ๐๐ผ๐บ๐บ๐ผ๐ป ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ โข Mixed content detection (HTTP resources on HTTPS pages) โข Forms submitting over insecure connections โข Missing CSRF token detection โข Password fields on non-HTTPS pages โข Credit card/SSN fields without HTTPS โข Inline event handlers (onclick, onload, etc.) โข JavaScript URLs and data: URLs โข eval() and dangerous DOM manipulation โข Exposed API keys and credentials in source ๐ก ๐๐ฑ๐ฑ๐ถ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ต๐ฒ๐ฐ๐ธ๐ โข Subresource Integrity (SRI) validation for CDN resources โข CORS configuration analysis โข Enhanced XSS detection with 10+ event handler types โข srcdoc attribute usage in iframes โข URL manipulation pattern detection โ๏ธ ๐๐ข๐ช ๐๐ง ๐ช๐ข๐ฅ๐๐ฆ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against a comprehensive vulnerability database with CVE tracking. No data leaves your machine. Results are presented with a 0โ100 security score using severity-based weighting (Critical/High/Medium/Low). A trend indicator (โ/โ/โ) shows how the score changed since your last scan of that domain. The OWASP tab maps every finding to the OWASP Top 10 (2021) so you can communicate risk in a language your team understands. Click any category to see specific findings with remediation guidance and CVE references. Every vulnerability includes a ๐ค Explain & Fix button with a plain-English explanation and a copy-paste code fix. Export as a formatted HTML report, machine-readable JSON, or SARIF 2.1.0 for CI/CD pipelines and client deliverables. ๐ฅ ๐ช๐๐ข ๐๐ง'๐ฆ ๐๐ข๐ฅ โข ๐จโ๐ป Frontend developers checking sites before deployment โข ๐ Security engineers doing quick reconnaissance โข ๐ DevOps teams validating production configurations โข ๐ฏ Penetration testers performing initial assessments โข ๐ผ Freelancers auditing client websites โข ๐ Students learning web security fundamentals โข ๐ Anyone concerned about website security ๐ง ๐ง๐๐๐๐ก๐๐๐๐ ๐๐๐ง๐๐๐๐ฆ Built on Manifest V3 with minimal permissions: โข activeTab โ access current page when you click scan โข scripting โ inject analysis code into the page โข storage โ cache scan results and history locally โข tabs โ read current tab URL for history tracking โข sidePanel โ enable the persistent side panel (v1.4.0) โข contextMenus โ add right-click scan option (v1.4.0) โข notifications โ optional alerts for critical findings (v1.4.0, opt-in) โจ New in v1.4.0: โข OWASP Top 10 (2021) compliance view โข AI-powered Explain & Fix for every finding โข Persistent side panel mode โข Toolbar badge with live issue count โข Network & API security scanning โข SARIF 2.1.0 export โข Keyboard shortcuts (Alt+Shift+S / Alt+Shift+P) โข Right-click context menu integration โข Configurable auto-scan (opt-in, off by default) โข Settings tab with notification and badge controls No telemetry. No external API calls. The entire codebase is open source if you want to audit it or contribute. ๐ซ ๐๐๐ ๐๐ง๐๐ง๐๐ข๐ก๐ฆ This is a passive scanner, not a penetration testing tool. It cannot: โข Test for server-side vulnerabilities (SQLi, SSRF, RCE, etc.) โข Intercept or modify HTTP traffic โข Perform authenticated scanning โข Detect all possible security issues โข Replace a proper security audit by professionals Think of it as a comprehensive health check and reconnaissance tool, not a replacement for professional security testing. ๐ต๏ธ ๐ฃ๐ฅ๐๐ฉ๐๐๐ฌ Zero data collection. No analytics. No tracking. No external servers. Everything stays on your device. Built by developers, for developers. No fluff, just useful security insights with real CVE tracking, OWASP mapping, and actionable remediation guidance.
0 out of 5No ratings
Details
- Version1.4.0
- UpdatedJune 20, 2026
- Size111KiB
- LanguagesEnglish (United States)
- Developer
Email
ashishjsharda@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site