SecuriScan - Web Security Analyzer
Overview
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
SecuriScan is a powerful Chrome extension that performs comprehensive passive security analysis on any website. Built for developers, security professionals, and anyone who wants quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. ๐ช๐๐๐ง'๐ฆ ๐ก๐๐ช ๐๐ก ๐ฉ๐ญ.๐ฎ.๐ฌ โข 6x more vulnerability coverage - now detects 35+ JavaScript libraries โข Enhanced sensitive data detection - 25+ patterns including cloud API keys โข New security checks: Subresource Integrity (SRI) and CORS validation โข Severity-based scoring system (Critical/High/Medium/Low) โข Dynamic vulnerability database for easy updates ๐ช๐๐๐ง ๐๐ง ๐๐ข๐๐ฆ When you click scan, SecuriScan analyzes the current page for security misconfigurations and vulnerabilities: ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฒ๐ฎ๐ฑ๐ฒ๐ฟ๐ (๐ญ๐ฌ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐) โข Content-Security-Policy (CSP) โข Strict-Transport-Security (HSTS) โข X-Frame-Options โข X-Content-Type-Options โข Referrer-Policy โข Permissions-Policy โข Cross-Origin-Opener-Policy โข Cross-Origin-Resource-Policy โข Cross-Origin-Embedder-Policy โข X-XSS-Protection ๐๐ผ๐ผ๐ธ๐ถ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ โข HttpOnly and Secure flag validation โข Session token exposure detection โข Sensitive cookie pattern matching โข SameSite attribute guidance ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ ๐๐ฎ๐๐ฎ๐ฆ๐ฐ๐ฟ๐ถ๐ฝ๐ ๐๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐ (๐ฏ๐ฑ+ ๐น๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ถ๐ฒ๐) ๐๐ณ๐ช๐ต๐ช๐ค๐ข๐ญ ๐๐ฆ๐ท๐ฆ๐ณ๐ช๐ต๐บ: โข Handlebars < 4.7.7 (arbitrary code execution) โข Socket.IO < 4.4.1 (CORS bypass) โข Minimist < 1.2.6 (prototype pollution) โข EJS < 3.1.7 (template injection) ๐๐ช๐จ๐ฉ ๐๐ฆ๐ท๐ฆ๐ณ๐ช๐ต๐บ: โข jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) โข AngularJS < 1.8.3 (CVE-2023-26116) โข Lodash < 4.17.21 (CVE-2021-23337, CVE-2020-28500) โข React < 16.14.0 (CVE-2021-23648) โข Vue.js < 2.6.14 (CVE-2021-3766) โข Marked < 4.0.10 (ReDoS and XSS) โข DOMPurify < 2.3.10 (XSS bypass) โข Express < 4.17.3 (open redirect) โข Webpack < 5.76.0 (cross-realm access) โข Underscore < 1.13.0 (code execution) โข Next.js < 12.3.2 (open redirect) โข Nuxt.js < 2.15.7 (directory traversal) โข Pug < 3.0.1 (code injection) ๐๐ฆ๐ฅ๐ช๐ถ๐ฎ ๐๐ฆ๐ท๐ฆ๐ณ๐ช๐ต๐บ: โข Bootstrap < 4.3.1 (CVE-2019-8331) โข Moment.js < 2.29.4 (CVE-2022-31129) โข Axios < 0.21.3 (SSRF) โข D3.js, Chart.js, DataTables, and more ๐ฆ๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐๐ฎ๐๐ฎ ๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ (๐ฎ๐ฑ+ ๐ฝ๐ฎ๐๐๐ฒ๐ฟ๐ป๐) ๐๐๐ ๐๐ฆ๐บ๐ด & ๐๐ฐ๐ฌ๐ฆ๐ฏ๐ด: โข AWS Access/Secret Keys โข Google API Keys & OAuth โข GitHub Personal Access Tokens โข Stripe API Keys (live & test) โข Slack Tokens โข Twilio, SendGrid, Mailgun API Keys โข PayPal Braintree Tokens โข Square OAuth Secrets โข Shopify Access Tokens & Shared Secrets โข Generic API key patterns ๐๐ณ๐ฆ๐ฅ๐ฆ๐ฏ๐ต๐ช๐ข๐ญ๐ด & ๐๐ฆ๐ค๐ณ๐ฆ๐ต๐ด: โข Private Keys (RSA, SSH, EC, PGP, OpenSSH) โข Database Connection Strings (MongoDB, MySQL, PostgreSQL) โข JWT Tokens โข Passwords in source code โข Firebase URLs ๐๐๐: โข Credit Card Patterns โข Social Security Numbers โข Email Addresses (filtered for false positives) ๐๐ผ๐บ๐บ๐ผ๐ป ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ โข Mixed content detection (HTTP resources on HTTPS pages) โข Forms submitting over insecure connections โข Missing CSRF token detection โข Password fields on non-HTTPS pages โข Credit card/SSN fields without HTTPS โข Inline event handlers (onclick, onload, etc.) โข JavaScript URLs and data: URLs โข eval() and dangerous DOM manipulation โข Exposed API keys and credentials in source ๐ก๐ฒ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ต๐ฒ๐ฐ๐ธ๐ โข Subresource Integrity (SRI) validation for CDN resources โข CORS configuration analysis โข Enhanced XSS detection with 10+ event handler types โข srcdoc attribute usage in iframes โข URL manipulation pattern detection ๐๐ข๐ช ๐๐ง ๐ช๐ข๐ฅ๐๐ฆ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against a comprehensive vulnerability database with CVE tracking. No data leaves your machine. Results are presented with a 0-100 security score using severity-based weighting (Critical/High/Medium/Low). Click any category to see specific findings with remediation guidance and CVE references. Export everything as a beautifully formatted HTML report for documentation or client deliverables. ๐ช๐๐ข ๐๐ง'๐ฆ ๐๐ข๐ฅ โข Frontend developers checking sites before deployment โข Security engineers doing quick reconnaissance โข DevOps teams validating production configurations โข Penetration testers performing initial assessments โข Freelancers auditing client websites โข Students learning web security fundamentals โข Anyone concerned about website security ๐ง๐๐๐๐ก๐๐๐๐ ๐๐๐ง๐๐๐๐ฆ Built on Manifest V3 with minimal permissions: โข activeTab - access current page when you click scan โข scripting - inject analysis code โข storage - cache last scan result locally ๐ก๐ฒ๐ ๐ถ๐ป ๐๐ญ.๐ฎ.๐ฌ: โข Modular vulnerability database architecture โข Dynamic configuration for easy updates โข Severity-based scoring algorithm โข Enhanced pattern matching with regex optimization โข Improved error handling and CORS fallbacks No background processes. No external API calls. No telemetry. The entire codebase is open source on GitHub if you want to audit it or contribute. ๐๐๐ ๐๐ง๐๐ง๐๐ข๐ก๐ฆ This is a passive scanner, not a penetration testing tool. It cannot: โข Test for server-side vulnerabilities (SQLi, SSRF, RCE, etc.) โข Intercept or modify HTTP traffic โข Perform authenticated scanning โข Detect all possible security issues โข Replace a proper security audit by professionals Think of it as a comprehensive health check and reconnaissance tool, not a replacement for professional security testing. ๐ฃ๐ฅ๐๐ฉ๐๐๐ฌ Zero data collection. No analytics. No tracking. No external servers. Everything stays on your device. Check the source code yourself - it's all on GitHub. ๐ข๐ฃ๐๐ก ๐ฆ๐ข๐จ๐ฅ๐๐ MIT licensed. PRs welcome. Found a bug or want to add detection for another vulnerable library? The vulnerability database is now modular and easy to extend. Open an issue or submit a pull request. GitHub: https://github.com/ashishjsharda/securiscan Built by developers, for developers. No fluff, just useful security insights with real CVE tracking and actionable remediation guidance.
0 out of 5No ratings
Details
- Version1.2.1
- UpdatedJanuary 9, 2026
- Size85.13KiB
- LanguagesEnglish (United States)
- Developer
Email
ashishjsharda@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site