Item logo image for Trufflehog-PingPwn

Trufflehog-PingPwn

Item media 3 (screenshot) for Trufflehog-PingPwn
Item media 1 (screenshot) for Trufflehog-PingPwn
Item media 2 (screenshot) for Trufflehog-PingPwn
Item media 3 (screenshot) for Trufflehog-PingPwn
Item media 1 (screenshot) for Trufflehog-PingPwn
Item media 1 (screenshot) for Trufflehog-PingPwn
Item media 2 (screenshot) for Trufflehog-PingPwn
Item media 3 (screenshot) for Trufflehog-PingPwn

Overview

Detects potential exposed secrets on web pages.

Trufflehog-PingPwn scans web pages and referenced resources for common secret patterns (API keys, tokens, private keys, webhook URLs) so you can identify accidental exposures quickly. Scanning and detection are performed entirely in your browser; this extension does not send findings to any remote server. Use the popup to review findings, clear them, or download a CSV of results. This extension tries to brings the scanning & Detection capabilities of well known Trufflehog to browser in real time scanning. Key features: - Detects generic API keys, specific provider tokens, and common secret formats. - Optionally checks for `.env` files and `.git` directories (may trigger server protections). - Shows per-origin findings with a badge count and in-popup listing. - Local-only storage of findings using the browser's storage; no remote transmission. Core Detection Features: - Detects API keys, tokens, private keys, and webhook URLs on web pages - Scans referenced resources (external scripts, .env files, .git directories) - Recognizes patterns from 30+ secret providers. - Supports generic secret patterns (API keys, database credentials, passwords) - Base64-encoded secret detection with automatic decoding - Real-time scanning as you browse UI & User Experience: - Clean, intuitive popup interface with toggle controls - Badge count on toolbar showing findings per origin - Per-origin findings list with detailed match information - One-click clearing of findings (current origin or all) - CSV export for audit trails and compliance reporting - Origin-based filtering and deny list to skip specific domains - Local notification alerts for critical findings (e.g., .git directories) - Customizable detection rule toggles (turn on/off specific categories) Privacy statement: All scanning and analysis occurs locally inside the browser. No findings, page contents, or extracted secrets are transmitted to external servers. The extension uses `chrome.storage.sync` to store settings and detected findings on your browser; you can clear stored findings via the popup. Developer contact: pingpwnsec@gmail.com Keywords: secrets, security, trufflehog, scan, credentials, api-keys, bugbounty, security, scanning, bug-bounty, developer-tools, exposure-detection, penetration-testing

Details

  • Version
    0.0.4
  • Updated
    December 30, 2025
  • Size
    39.07KiB
  • Languages
    English
  • Developer
    Email
    pingpwnsec@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

HackBar

4.2

A browser extension for Penetration Testing

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

FoxyProxy

3.8

Easy to use advanced Proxy Management tool for everyone

Retire.JS

5.0

Scanning website for vulnerable js libraries. Icon by studiomx

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

EndPointer

5.0

An endpoint parser and extractor with many flexible features

DotGit

4.8

An extension for checking if .git is exposed in visited websites

Hack-Tools

4.6

The all in one Red team extension for web pentester

JS Recon Buddy

5.0

Analyze page scripts for bug bounty reconnaissance.

HackBar

4.2

A browser extension for Penetration Testing

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

FoxyProxy

3.8

Easy to use advanced Proxy Management tool for everyone

Retire.JS

5.0

Scanning website for vulnerable js libraries. Icon by studiomx

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

Google apps