Item logo image for Jsmon Security Analyzer — Web Security Inspector

Jsmon Security Analyzer — Web Security Inspector

jsmon.sh
5.0(

3 ratings

)
ExtensionDeveloper Tools150 users
Item media 4 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 1 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 2 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 3 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 4 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 1 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 1 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 2 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 3 (screenshot) for Jsmon Security Analyzer — Web Security Inspector
Item media 4 (screenshot) for Jsmon Security Analyzer — Web Security Inspector

Overview

Detects exposed secrets, shadow APIs, and supply chain risks by scanning web resources. Powered by Jsmon.

## Jsmon Security Analyzer — Browser Extension Automatically capture and analyze web traffic directly from your browser. Every JavaScript file, API response, config, and document is sent to Jsmon's engine for real-time security analysis — no manual uploads, no proxies required. ### What it detects - **Exposed secrets** — API keys, tokens, credentials leaked in JS or config files - **Shadow APIs** — undocumented or forgotten endpoints buried in frontend code - **Supply chain risks** — vulnerable or suspicious NPM packages loaded at runtime - **Sensitive data exposure** — PII, internal paths, environment variables - **Misconfigured assets** — insecure headers, open redirects, debug artifacts ### Supported file types: 20+ extensions ### How it works 1. Install the extension and connect your Jsmon account 2. Browse normally — the extension passively captures traffic 3. Matched file types are forwarded to Jsmon for deep analysis 4. View findings in your Jsmon dashboard: secrets, APIs, risks, asset inventory ### Who it's for - **Security engineers** running recon or pen tests on web applications - **AppSec & EASM teams** monitoring their organization's external attack surface - **Bug bounty hunters** accelerating JS recon workflows - **CISOs & compliance teams** enforcing continuous visibility across web assets ### About Jsmon Jsmon is an AI-powered External Attack Surface Management platform trusted by security teams worldwide. Built by practitioners, for practitioners. 🔗 jsmon.sh

Details

  • Version
    1.5
  • Updated
    June 17, 2026
  • Size
    2.06MiB
  • Languages
    English
  • Developer
    Website
    Email
    support@jsmon.sh
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Jsmon Security Analyzer — Web Security Inspector has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Jsmon Security Analyzer — Web Security Inspector handles the following:

Authentication information
Web history
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps