Item logo image for Jsmon Extension

Jsmon Extension

jsmon.sh
5.0(

3 ratings

)
Item media 4 (screenshot) for Jsmon Extension
Item media 1 (screenshot) for Jsmon Extension
Item media 2 (screenshot) for Jsmon Extension
Item media 3 (screenshot) for Jsmon Extension
Item media 4 (screenshot) for Jsmon Extension
Item media 1 (screenshot) for Jsmon Extension
Item media 1 (screenshot) for Jsmon Extension
Item media 2 (screenshot) for Jsmon Extension
Item media 3 (screenshot) for Jsmon Extension
Item media 4 (screenshot) for Jsmon Extension

Overview

Security Scans on your browser's network history in the background

## Jsmon Security Analyzer | Browser Extension Automatically capture and analyze web traffic directly from your browser. Every JavaScript file, API response, config, and document is sent to Jsmon's engine for real-time security analysis — no manual uploads, no proxies required. ### What it detects - **Exposed secrets** — API keys, tokens, credentials leaked in JS or config files - **Shadow APIs** — undocumented or forgotten endpoints buried in frontend code - **Supply chain risks** — vulnerable or suspicious NPM packages loaded at runtime - **Sensitive data exposure** — PII, internal paths, environment variables - **Misconfigured assets** — insecure headers, open redirects, debug artifacts ### Supported file types: 20+ extensions ### How it works 1. Install the extension and connect your Jsmon account 2. Browse normally — the extension passively captures traffic 3. Matched file types are forwarded to Jsmon for deep analysis 4. View findings in your Jsmon dashboard: secrets, APIs, risks, asset inventory ### Who it's for - **Security engineers** running recon or pen tests on web applications - **AppSec & EASM teams** monitoring their organization's external attack surface - **Bug bounty hunters** accelerating JS recon workflows - **CISOs & compliance teams** enforcing continuous visibility across web assets ### About Jsmon Jsmon is an AI-powered External Attack Surface Management platform trusted by security teams worldwide. Built by practitioners, for practitioners. 🔗 jsmon.sh

Details

  • Version
    2.1
  • Updated
    July 10, 2026
  • Size
    2.06MiB
  • Languages
    English
  • Developer
    Website
    Email
    support@jsmon.sh
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Jsmon Extension has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Jsmon Extension handles the following:

Authentication information
Web history
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

DOM XSS Highlighter — Pro

0.0

Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.

Hack-Tools

4.5

The all in one Red team extension for web pentester

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

DOMLogger++

5.0

DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

EndPointer

5.0

An endpoint parser and extractor with many flexible features

Endpoint Extractor

5.0

Extracts endpoints from the current page.

postLogger

5.0

Extension to log postMessage()

Gecko

5.0

Automated CSPT discovery tool

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

DOM XSS Highlighter — Pro

0.0

Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.

Hack-Tools

4.5

The all in one Red team extension for web pentester

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

DOMLogger++

5.0

DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

EndPointer

5.0

An endpoint parser and extractor with many flexible features

Google apps