Item logo image for Silent Recon

Silent Recon

Item media 2 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 2 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 2 (screenshot) for Silent Recon

Overview

Passive and extensible web security scanner. Detects CORS flaws, missing headers, exposed APIs.

Silent Recon is a passive browser extension that scans for common web security misconfigurations while you browse. I built this extension to help users analyze security flaws in real time during their web application testing. Whether you're a bug bounty hunter, red teamer, or security-conscious developer, Silent Recon helps you catch misconfigurations that attackers can exploit including missing security headers, CORS misuses, exposed APIs, and more. Features as of now: - Detects CORS misconfigurations (wildcard + credentials) - Flags missing HTTP security headers (CSP, HSTS, etc.) - Identifies API endpoints and passive JSON exposure - Works automatically while browsing once enabled no manual scanning - Toggle on/off control to enable scanning when needed - Domain filter - Clear all findings anytime All detection happens locally. No data is sent to external servers. Built with privacy and security best practices in mind. More features are on the way, Thank you!

Details

  • Version
    0.3
  • Updated
    November 17, 2025
  • Offered by
    Popeanga78
  • Size
    9.74KiB
  • Languages
    English
  • Developer
    Popeanga Petrut-Gabriel
    Strada Rezervelor NR. 58C Roșu, Ilfov 077040 RO
    Email
    popeanga78@gmail.com
    Phone
    +40 725 720 772
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.

Privacy

The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

CORS Unblock

4.8

Temporarily unblock CORS for development and testing purposes

RePostman

4.7

A Postman-like Chrome extension for API testing and debugging

Network Pentesting Toolkit - VAPT

0.0

Cybersecurity extension for VAPT, pentesting, and security testing. Includes port exploits, cheatsheets & tools.

VAPT Assistant Pro+

0.0

Advanced VAPT toolkit with AI, security headers, WAF detection, DNS/WHOIS tools, subdomain scanner, and VirusTotal integration.

API Tester - REST API Tester Client FREE

5.0

Develop, test and debug REST APIs.

ZeroThreat AI Recorder – Most Intelligent DAST Tool

4.4

Automate threat & vulnerability detection (OWASP Top 10) for web apps & APIs. Fits developers & pentesters.

Vulners Lookup

5.0

Automatically detect and highlight CVE IDs on web pages with vulnerability information from Vulners.com

CyberArk Secure Web Sessions Extension

3.5

Protect web-apps with CyberArk Secure Web Sessions. Offers step-recording, continuous authentication, and session protection.

Hive - Extension Detector

0.0

Detect enabled Chrome extensions to ensure a fair and secure Hive Smart Interviews assessment.

Malware & Vulnerability Scanner

0.0

A Chrome extension for scanning files, URLs, and analyzing CVE vulnerabilities

Browse.live Web Safety

4.6

Browser Extension that Hides Unfair Ads and Unsafe Search Results

Extension Auditor Pro - Assess Risk & Improve Browser Security Posture

5.0

Assess, and monitor browser extensions for security and privacy risks. Improve your Browser Security Posture and Stay Safe Oonline.

CORS Unblock

4.8

Temporarily unblock CORS for development and testing purposes

RePostman

4.7

A Postman-like Chrome extension for API testing and debugging

Network Pentesting Toolkit - VAPT

0.0

Cybersecurity extension for VAPT, pentesting, and security testing. Includes port exploits, cheatsheets & tools.

VAPT Assistant Pro+

0.0

Advanced VAPT toolkit with AI, security headers, WAF detection, DNS/WHOIS tools, subdomain scanner, and VirusTotal integration.

API Tester - REST API Tester Client FREE

5.0

Develop, test and debug REST APIs.

ZeroThreat AI Recorder – Most Intelligent DAST Tool

4.4

Automate threat & vulnerability detection (OWASP Top 10) for web apps & APIs. Fits developers & pentesters.

Vulners Lookup

5.0

Automatically detect and highlight CVE IDs on web pages with vulnerability information from Vulners.com

CyberArk Secure Web Sessions Extension

3.5

Protect web-apps with CyberArk Secure Web Sessions. Offers step-recording, continuous authentication, and session protection.

Google apps