Item logo image for JS Finder Pro

JS Finder Pro

Item media 2 (screenshot) for JS Finder Pro
Item media 1 (screenshot) for JS Finder Pro
Item media 2 (screenshot) for JS Finder Pro
Item media 1 (screenshot) for JS Finder Pro
Item media 1 (screenshot) for JS Finder Pro
Item media 2 (screenshot) for JS Finder Pro

Overview

Professional JavaScript reconnaissance tool. Extract endpoints, secrets, directories, and sensitive URLs from any webpage.

JS Finder Pro is a professional JavaScript reconnaissance tool for security researchers, bug bounty hunters, and developers who need to quickly analyze what a webpage is exposing through its scripts. How it works: Click Scan on any webpage. The extension fetches every JavaScript file loaded on the page, scans inline scripts, and optionally follows linked scripts recursively (Deep Scan mode). Results are organized across four tabs: 🌐 Endpoints — URLs, API paths, WebSocket connections, and internal routes found in JavaScript. Sensitive paths such as admin panels, config routes, and internal APIs are flagged automatically. šŸ”‘ Secrets — Detects accidentally exposed credentials and tokens across major cloud providers, payment processors, source control platforms, communication services, and databases. Secret values are blurred by default and revealed on click. šŸ“ Directories — Sensitive path references are extracted and ranked by risk level: critical, high, or medium. ⚔ JS Files — A full list of every JavaScript file loaded on the page, including files discovered during Deep Scan. Export findings as JSON or CSV for reporting, or copy to clipboard in one click. Who it's for: Bug bounty hunters doing recon on in-scope targets Penetration testers auditing web applications Developers checking their own apps for accidental secret exposure Security engineers reviewing third-party JavaScript for supply chain risk All scanning runs entirely in your browser. No data is sent to any external server.

Details

  • Version
    3.0.1
  • Updated
    August 27, 2026
  • Size
    23.96KiB
  • Languages
    English
  • Developer
    Email
    omaralgbry1@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

JS Finder

0.0

Scan JavaScript files on any webpage and extract endpoints, APIs, and URLs for security research and development analysis.

BrowserLeaks — Privacy & Fingerprint Scanner

0.0

Browser fingerprint, WebRTC/DNS leak tests, and privacy tools — the full BrowserLeaks site in your browser side panel.

API finder

5.0

Passive API discovery tool for security testers. Discovers API endpoints from browser traffic, flags risks, exports OpenAPI/Postman.

JS Injector

0.0

Inject custom JavaScript into any website. Manage userscripts with URL matching, context menus, and import/export.

JS Library Detector

0.0

A simple tool that detects and lists JS libraries used by the currently webpage, and lets you copy them to the clipboard.

Next.js Detector

5.0

Comprehensive Next.js detection tool - detects version, router type, features, deployment platform, and more.

Token Manager Pro

5.0

Grab, inject, and capture authentication tokens from web pages

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

Wayback Recon Pro

5.0

Reconnaissance toolkit for Wayback Machine archives. Extract URLs, subdomains, parameters, and sensitive files.

HackTools++

4.9

HackTools++: Repeater, Intruder, Decoder, and Scanner in DevTools. Capture, edit, and replay HTTP requests for testing.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

SecretSifter: Live Credentials & Secrets Scanner

5.0

Detects secrets, API keys, and tokens in JS, JSON, XML, and HTML at runtime

JS Finder

0.0

Scan JavaScript files on any webpage and extract endpoints, APIs, and URLs for security research and development analysis.

BrowserLeaks — Privacy & Fingerprint Scanner

0.0

Browser fingerprint, WebRTC/DNS leak tests, and privacy tools — the full BrowserLeaks site in your browser side panel.

API finder

5.0

Passive API discovery tool for security testers. Discovers API endpoints from browser traffic, flags risks, exports OpenAPI/Postman.

JS Injector

0.0

Inject custom JavaScript into any website. Manage userscripts with URL matching, context menus, and import/export.

JS Library Detector

0.0

A simple tool that detects and lists JS libraries used by the currently webpage, and lets you copy them to the clipboard.

Next.js Detector

5.0

Comprehensive Next.js detection tool - detects version, router type, features, deployment platform, and more.

Token Manager Pro

5.0

Grab, inject, and capture authentication tokens from web pages

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

Google apps