Item logo image for Silent Recon

Silent Recon

silent-recon.com
ExtensionDeveloper Tools9 users
Item media 5 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 2 (screenshot) for Silent Recon
Item media 3 (screenshot) for Silent Recon
Item media 4 (screenshot) for Silent Recon
Item media 5 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 1 (screenshot) for Silent Recon
Item media 2 (screenshot) for Silent Recon
Item media 3 (screenshot) for Silent Recon
Item media 4 (screenshot) for Silent Recon
Item media 5 (screenshot) for Silent Recon

Overview

Passive and extensible web security scanner. Detects CORS flaws, missing headers, exposed APIs.

Silent Recon is a browser-native security reconnaissance extension for authorized web application testing. It passively observes pages, requests, response headers, scripts, and API activity while you browse, then turns those signals into local findings and dashboard views. I built it for bug bounty hunters, red teamers, security engineers, and developers who want a faster way to spot web security misconfigurations and attack-surface clues during normal testing. The latest features of version 1.0 are: - Detects CORS misconfigurations, including wildcard CORS with credentials - Flags missing HTTP security headers such as CSP, HSTS, X-Frame-Options, Referrer-Policy, and related hardening headers - Identifies API endpoints, GraphQL activity, JavaScript assets, and exposed API documentation paths - Highlights auth/session indicators, sensitive JSON patterns, token-like values, privileged routes, and input-risk candidates - Builds endpoint maps, script intelligence, auth profiles, workflow chains, saved targets, and browsing sessions - Includes approved-target mode, target lock, first-party filtering, noise suppression, and clear/export controls - Provides a free local preview with optional Pro features for deeper triage, retention, workflow views, and export Silent Recon is passive: it does not attack, fuzz, exploit, brute force, or modify traffic. It is intended only for systems and applications where you have permission to perform security testing. Scan findings and browsing-derived reconnaissance data are processed and stored locally in the browser extension. Silent Recon does not sell user data or use it for advertising. License activation and validation, if used, are handled through silent-recon.com.

Details

  • Version
    1.0.0
  • Updated
    May 14, 2026
  • Features
    Offers in-app purchases
  • Size
    72.97KiB
  • Languages
    English
  • Developer
    Popeanga Petrut-Gabriel
    Strada Rezervelor NR. 58C Roșu, Ilfov 077040 RO
    Website
    Email
    popeanga78@gmail.com
    Phone
    +40 725 720 772
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.

Privacy

Manage extensions and learn how they're being used in your organization

Silent Recon has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Silent Recon handles the following:

Authentication information
Web history
User activity
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps