JS Finder Pro
Overview
Professional JavaScript reconnaissance tool. Extract endpoints, secrets, directories, and sensitive URLs from any webpage.
JS Finder Pro is a professional JavaScript reconnaissance tool for security researchers, bug bounty hunters, and developers who need to quickly analyze what a webpage is exposing through its scripts. How it works: Click Scan on any webpage. The extension fetches every JavaScript file loaded on the page, scans inline scripts, and optionally follows linked scripts recursively (Deep Scan mode). Results are organized across four tabs: š Endpoints ā URLs, API paths, WebSocket connections, and internal routes found in JavaScript. Sensitive paths such as admin panels, config routes, and internal APIs are flagged automatically. š Secrets ā Detects accidentally exposed credentials and tokens across major cloud providers, payment processors, source control platforms, communication services, and databases. Secret values are blurred by default and revealed on click. š Directories ā Sensitive path references are extracted and ranked by risk level: critical, high, or medium. ā” JS Files ā A full list of every JavaScript file loaded on the page, including files discovered during Deep Scan. Export findings as JSON or CSV for reporting, or copy to clipboard in one click. Who it's for: Bug bounty hunters doing recon on in-scope targets Penetration testers auditing web applications Developers checking their own apps for accidental secret exposure Security engineers reviewing third-party JavaScript for supply chain risk All scanning runs entirely in your browser. No data is sent to any external server.
0 out of 5No ratings
Details
- Version3.0.1
- UpdatedAugust 27, 2026
- Size23.96KiB
- LanguagesEnglish
- Developer
Email
omaralgbry1@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes