Khoj Webscan
Overview
Passive OWASP scanner with AI explanation layer.
Passive OWASP scanner for Chrome with AI-backed, on-demand explanations using your own Anthropic/Gemini/DeepSeek key. Khoj Webscan passively inspects the page you’re viewing and highlights OWASP-aligned security issues without sending payloads or fuzzing inputs. It checks response headers, cookies, DOM resources, inline scripts, and loaded assets to surface missing/weak security controls, mixed content, missing SRI, insecure cookie flags, and other passive risks. Key benefits: Passive browser-only scanning: no active probing, only what the page already exposes OWASP-aligned findings with exact evidence and remediation guidance Per-finding AI explanation on demand, using your own provider key Redaction preview before any provider request is sent Local-only API key storage (chrome.storage.local, never sync) Severity-ranked exported reports for security reviews and audits Privacy / trust note Your API key stays local and provider calls happen directly from your machine. Sensitive values are redacted before being sent, and explanation requests are cached locally for up to 7 days.
0 out of 5No ratings
Details
- Version0.2.0
- UpdatedAugust 4, 2026
- Size198KiB
- LanguagesEnglish (United Kingdom)
- Developer
Email
patraanup123@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes