SecuriScan - Web Security Analyzer
Overview
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
SecuriScan is a powerful Chrome extension that performs comprehensive passive security analysis on any website. Built for developers, security professionals, and anyone who wants quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. ๐ ๐ช๐๐๐ง'๐ฆ ๐ก๐๐ช ๐๐ก ๐ฉ๐ญ.๐ฏ.๐ฌ โข ๐ Privacy tracker detection โ flags 18 third-party trackers including Meta Pixel, TikTok, Hotjar, FullStory, and more โข ๐พ Browser storage audit โ scans localStorage and sessionStorage for exposed tokens, keys, and PII โข ๐ Scan history & score trends โ tracks your last 10 scans per domain and shows โ/โ trend on every result โข ๐ JSON export โ export results as machine-readable JSON alongside the existing HTML report ๐ ๐ช๐๐๐ง ๐๐ง ๐๐ข๐๐ฆ When you click scan, SecuriScan analyzes the current page for security misconfigurations and vulnerabilities across 12 categories: ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฒ๐ฎ๐ฑ๐ฒ๐ฟ๐ (๐ญ๐ฌ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐) โข Content-Security-Policy (CSP) โข Strict-Transport-Security (HSTS) โข X-Frame-Options โข X-Content-Type-Options โข Referrer-Policy โข Permissions-Policy โข Cross-Origin-Opener-Policy โข Cross-Origin-Resource-Policy โข Cross-Origin-Embedder-Policy โข X-XSS-Protection ๐ช ๐๐ผ๐ผ๐ธ๐ถ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ โข HttpOnly and Secure flag validation โข Session token exposure detection โข Sensitive cookie pattern matching โข SameSite attribute guidance ๐ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ ๐๐ฎ๐๐ฎ๐ฆ๐ฐ๐ฟ๐ถ๐ฝ๐ ๐๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐ (๐ฏ๐ฑ+ ๐น๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐) ๐ด Critical Severity: โข Handlebars < 4.7.7 (arbitrary code execution) โข Socket.IO < 4.4.1 (CORS bypass) โข Minimist < 1.2.6 (prototype pollution) โข EJS < 3.1.7 (template injection) ๐ High Severity: โข jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) โข AngularJS < 1.8.3 (CVE-2023-26116) โข Lodash < 4.17.21 (CVE-2021-23337, CVE-2020-28500) โข React < 16.14.0 (CVE-2021-23648) โข Vue.js < 2.6.14 (CVE-2021-3766) โข Marked < 4.0.10 (ReDoS and XSS) โข DOMPurify < 2.3.10 (XSS bypass) โข Express < 4.17.3 (open redirect) โข Webpack < 5.76.0 (cross-realm access) โข Underscore < 1.13.0 (code execution) โข Next.js < 12.3.2 (open redirect) โข Nuxt.js < 2.15.7 (directory traversal) โข Pug < 3.0.1 (code injection) ๐ก Medium Severity: โข Bootstrap < 4.3.1 (CVE-2019-8331) โข Moment.js < 2.29.4 (CVE-2022-31129) โข Axios < 0.21.3 (SSRF) โข D3.js, Chart.js, DataTables, and more ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐๐ฎ๐๐ฎ ๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ (๐ฎ๐ฑ+ ๐ฝ๐ฎ๐๐๐ฒ๐ฟ๐ป๐) ๐ API Keys & Tokens: โข AWS Access/Secret Keys โข Google API Keys & OAuth โข GitHub Personal Access Tokens โข Stripe API Keys (live & test) โข Slack Tokens โข Twilio, SendGrid, Mailgun API Keys โข PayPal Braintree Tokens โข Square OAuth Secrets โข Shopify Access Tokens & Shared Secrets โข Generic API key patterns ๐ Credentials & Secrets: โข Private Keys (RSA, SSH, EC, PGP, OpenSSH) โข Database Connection Strings (MongoDB, MySQL, PostgreSQL) โข JWT Tokens โข Passwords in source code โข Firebase URLs ๐ชช PII: โข Credit Card Patterns โข Social Security Numbers โข Email Addresses (filtered for false positives) ๐ ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐ง๐ฟ๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ (๐ก๐๐ช) Detects 18 third-party tracking scripts that collect and share your users' behavioral data: โข ๐ฅ Session recorders: Hotjar, FullStory, Mouseflow, Crazy Egg โข ๐ข Ad pixels: Meta/Facebook, TikTok, Twitter/X, LinkedIn Insight โข ๐ Analytics: Google Analytics, Google Tag Manager, Mixpanel, Amplitude, Heap, Clarity โข ๐ฌ CRM: HubSpot, Intercom, Pardot, Segment Each tracker is rated by severity โ session recorders (high) vs. analytics-only (medium) โ so you know which ones are most invasive. ๐พ ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ ๐ฆ๐๐ผ๐ฟ๐ฎ๐ด๐ฒ ๐๐๐ฑ๐ถ๐ (๐ก๐๐ช) Scans localStorage and sessionStorage for sensitive data that XSS could steal: โข Auth tokens, JWT, session IDs stored under sensitive key names โข API keys, AWS credentials, private keys in stored values โข Credit card numbers and SSNs โข Flags risky storage patterns and recommends HttpOnly cookies instead โ ๏ธ ๐๐ผ๐บ๐บ๐ผ๐ป ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ โข Mixed content detection (HTTP resources on HTTPS pages) โข Forms submitting over insecure connections โข Missing CSRF token detection โข Password fields on non-HTTPS pages โข Credit card/SSN fields without HTTPS โข Inline event handlers (onclick, onload, etc.) โข JavaScript URLs and data: URLs โข eval() and dangerous DOM manipulation โข Exposed API keys and credentials in source ๐ก ๐๐ฑ๐ฑ๐ถ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ต๐ฒ๐ฐ๐ธ๐ โข Subresource Integrity (SRI) validation for CDN resources โข CORS configuration analysis โข Enhanced XSS detection with 10+ event handler types โข srcdoc attribute usage in iframes โข URL manipulation pattern detection โ๏ธ ๐๐ข๐ช ๐๐ง ๐ช๐ข๐ฅ๐๐ฆ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against a comprehensive vulnerability database with CVE tracking. No data leaves your machine. Results are presented with a 0-100 security score using severity-based weighting (Critical/High/Medium/Low). A trend indicator (โ/โ/โ) shows how the score changed since your last scan of that domain. Click any category to see specific findings with remediation guidance and CVE references. Export as a formatted HTML report or machine-readable JSON for CI/CD pipelines and client deliverables. ๐ฅ ๐ช๐๐ข ๐๐ง'๐ฆ ๐๐ข๐ฅ โข ๐จโ๐ป Frontend developers checking sites before deployment โข ๐ Security engineers doing quick reconnaissance โข ๐ DevOps teams validating production configurations โข ๐ฏ Penetration testers performing initial assessments โข ๐ผ Freelancers auditing client websites โข ๐ Students learning web security fundamentals โข ๐ Anyone concerned about website security ๐ง ๐ง๐๐๐๐ก๐๐๐๐ ๐๐๐ง๐๐๐๐ฆ Built on Manifest V3 with minimal permissions: โข activeTab โ access current page when you click scan โข scripting โ inject analysis code โข storage โ cache scan results and history locally โจ New in v1.3.0: โข Privacy tracker detection (18 trackers across 6 categories) โข Browser storage security audit โข Per-domain scan history with score trend tracking โข JSON export for CI/CD and tooling integration No background processes. No external API calls. No telemetry. The entire codebase is open source on GitHub if you want to audit it or contribute. ๐ซ ๐๐๐ ๐๐ง๐๐ง๐๐ข๐ก๐ฆ This is a passive scanner, not a penetration testing tool. It cannot: โข Test for server-side vulnerabilities (SQLi, SSRF, RCE, etc.) โข Intercept or modify HTTP traffic โข Perform authenticated scanning โข Detect all possible security issues โข Replace a proper security audit by professionals Think of it as a comprehensive health check and reconnaissance tool, not a replacement for professional security testing. ๐ต๏ธ ๐ฃ๐ฅ๐๐ฉ๐๐๐ฌ Zero data collection. No analytics. No tracking. No external servers. Everything stays on your device. Check the source code yourself โ it's all on GitHub. ๐ป ๐ข๐ฃ๐๐ก ๐ฆ๐ข๐จ๐ฅ๐๐ MIT licensed. PRs welcome. Found a bug or want to add detection for another vulnerable library or tracker? The vulnerability database is modular and easy to extend. Open an issue or submit a pull request. GitHub: https://github.com/ashishjsharda/securiscan Built by developers, for developers. No fluff, just useful security insights with real CVE tracking and actionable remediation guidance.
0 out of 5No ratings
Details
- Version1.3.0
- UpdatedMay 14, 2026
- Size87.72KiB
- LanguagesEnglish (United States)
- Developer
Email
ashishjsharda@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site