SecuriScan - Web Security Analyzer
Overview
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
SecuriScan is a lightweight Chrome extension that performs passive security analysis on any website. Built for developers who want quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. ๐ช๐๐๐ง ๐๐ง ๐๐ข๐๐ฆ When you click scan, SecuriScan analyzes the current page for common security misconfigurations: ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฒ๐ฎ๐ฑ๐ฒ๐ฟ๐ โข Content-Security-Policy (CSP) โข Strict-Transport-Security (HSTS) โข X-Frame-Options โข X-Content-Type-Options โข Referrer-Policy โข Permissions-Policy ๐๐ผ๐ผ๐ธ๐ถ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ โข HttpOnly and Secure flag validation โข Session token exposure detection โข SameSite attribute checking ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ ๐๐ฎ๐๐ฎ๐ฆ๐ฐ๐ฟ๐ถ๐ฝ๐ ๐๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐ โข jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) โข AngularJS < 1.8.0 (CVE-2022-25869) โข Lodash < 4.17.21 (CVE-2021-23337) โข Bootstrap < 4.3.1 (CVE-2019-8331) โข Moment.js < 2.29.4 (CVE-2022-31129) ๐๐ผ๐บ๐บ๐ผ๐ป ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ โข Mixed content (HTTP resources on HTTPS pages) โข Forms submitting over insecure connections โข Missing CSRF tokens โข Inline event handlers and eval() usage โข Exposed API keys, AWS credentials, JWT tokens in source ๐๐ข๐ช ๐๐ง ๐ช๐ข๐ฅ๐๐ฆ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against known vulnerability signatures. No data leaves your machine. Results are presented with a 0-100 security score, broken down by category. Click any category to see specific findings with remediation guidance. Export everything as a formatted HTML report for documentation or client deliverables. ๐ช๐๐ข ๐๐ง'๐ฆ ๐๐ข๐ฅ โข Frontend developers checking sites before deployment โข Security engineers doing quick recon โข DevOps teams validating production configurations โข Freelancers auditing client websites โข Students learning web security fundamentals ๐ง๐๐๐๐ก๐๐๐๐ ๐๐๐ง๐๐๐๐ฆ Built on Manifest V3 with minimal permissions: โข activeTab - access current page when you click scan โข scripting - inject analysis code โข storage - cache last scan result locally No background processes. No external API calls. No telemetry. The entire codebase is open source on GitHub if you want to audit it or contribute. ๐๐๐ ๐๐ง๐๐ง๐๐ข๐ก๐ฆ This is a passive scanner, not a penetration testing tool. It cannot: โข Test for server-side vulnerabilities (SQLi, SSRF, etc.) โข Intercept or modify HTTP traffic โข Perform authenticated scanning โข Replace a proper security audit Think of it as a quick health check, not a comprehensive security assessment. ๐ฃ๐ฅ๐๐ฉ๐๐๐ฌ Zero data collection. No analytics. No tracking. Everything stays on your device. Check the source code yourself - it's all on GitHub. ๐ข๐ฃ๐๐ก ๐ฆ๐ข๐จ๐ฅ๐๐ MIT licensed. PRs welcome. Found a bug or want to add detection for another vulnerable library? Open an issue or submit a pull request. GitHub: https://github.com/ashishjsharda/securiscan Built by developers, for developers. No fluff, just useful security insights.
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedNovember 17, 2025
- Size28.19KiB
- LanguagesEnglish (United States)
- Developer
Email
ashishjsharda@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site