Item logo image for Vibe Vulnerability Scanner

Vibe Vulnerability Scanner

5.0(

1 rating

)
ExtensionDeveloper Tools28 users
Item media 4 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 2 (screenshot) for Vibe Vulnerability Scanner
Item media 3 (screenshot) for Vibe Vulnerability Scanner
Item media 4 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 2 (screenshot) for Vibe Vulnerability Scanner
Item media 3 (screenshot) for Vibe Vulnerability Scanner
Item media 4 (screenshot) for Vibe Vulnerability Scanner

Overview

Scans web applications for security vulnerabilities

Catch exploitable vulnerabilities before attackers do. Vibe Vulnerability Scanner performs real-time security scanning of web applications using OSV.dev, the CISA Known Exploited Vulnerabilities catalog, and the GitHub Advisory Database. 🔍 KEY FEATURES • Real-time Scanning - Automatic detection on page load, plus SPA support via MutationObserver for React/Vue/Angular apps • OSV.dev Integration - Checks detected libraries against the open-source vulnerability database (no API key required) • CISA KEV Correlation - Cross-references official Known Exploited Vulnerabilities catalog • GitHub Advisory Database - Additional vulnerability coverage for npm packages • Supply Chain Detection - Flags typosquatted package names using edit-distance analysis against 75 popular npm packages • Source Map Analysis - Recovers bundled dependencies from .map files and checks them for known vulnerabilities • Cookie Security Audit - Detects missing Secure, HttpOnly, and SameSite flags • Persistent History - Stores last 50 scans per domain • Export Results - Download findings as JSON, CSV, or SARIF 2.1 (compatible with GitHub Advanced Security and CI pipelines) • Optional LLM Analys - Anthropic-powered taint analysis and secret validation (requires your own API key, disabled by default) • Settings Page - Configure API keys, severity filters, and suppressed domains 🛡️ WHAT GETS SCANNED Confirmed Issues: ✓ HTTP Scripts - Loading scripts over insecure HTTP ✓ Missing SRI - CDN scripts without Subresource Integrity checks ✓ Vulnerable Libraries - Matched against OSV.dev, CISA KEV, GitHub Advisory ✓ Weak CSP - unsafe-inline or unsafe-eval in Content Security Policy ✓ Missing Security Headers - HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy ✓ Insecure Cookies - Missing Secure, HttpOnly, or SameSite attributes ✓ Exposed Secrets - API keys, tokens, private keys in page source Heuristic Patterns (Require Verification): • Prototype Pollution - Dangerous __proto__ and constructor.prototype patterns • postMessage Without Origin Check - Message handlers missing event.origin validation • Inline Event Handlers - onclick, onerror, and similar attributes • innerHTML Usage - Potential XSS sinks • Typosquatting Risk - Package names suspiciously similar to popular libraries 📊 UNDERSTANDING RESULTS Severity: CRITICAL / HIGH / MEDIUM / LOW Confidence: high (confirmed) / medium (heuristic) / low (informational) 🔒 SECURITY & PRIVACY ✓ No Personal Data Collected - The extension does not collect, store, or transmit any personal information ✓ External API Calls Use No Credentials - Package names and versions are sent to OSV.dev and GitHub Advisory API to check for vulnerabilities. No page content or personal data is included ✓ LLM Analysis Is Opt-In - Code snippets are only sent to Anthropic if you enable this feature and supply your own API key ✓ Local Storage Only - Scan history and settings are stored on your device ✓ Safe Rendering - All results displayed via DOM APIs, no innerHTML ✓ Open Source - Full source code on GitHub 🎯 PERFECT FOR • Security Professionals - Quick vulnerability assessment • Penetration Testers - Initial reconnaissance • Web Developers - Security hygiene checks during development • DevSecOps Teams - Shift-left security testing • Bug Bounty Hunters - Fast initial scanning 💡 HOW IT WORKS 1. Detects JavaScript libraries from script tags, globals, and source maps 2. Queries OSV.dev and GitHub Advisory for known vulnerabilities 3. Cross-references CISA KEV for actively exploited issues 4. Checks cookies, headers, and DOM patterns locally 5. Provides severity ratings and actionable remediation guidance 🚀 GETTING STARTED 1. Install the extension 2. Navigate to any website 3. Click the extension icon to view findings 4. Expand any finding for details and remediation 5. Export as JSON, CSV, or SARIF for your workflow GitHub: https://github.com/ramukallepalli/vibe-vuln-scanner Privacy Policy:https://ramukallepalli.github.io/vibe-vuln-scanner/privacy-policy.html Report Issues: https://github.com/ramukallepalli/vibe-vuln-scanner/issues Powered by Powered by OSV.dev, CISA KEV, and GitHub Advisory Database.

Details

  • Version
    1.3.0
  • Updated
    July 26, 2026
  • Offered by
    ramu.kallepalli
  • Size
    10.05MiB
  • Languages
    English (United States)
  • Developer
    Ramu Kallepalli
    632 Allison Ln San Marcos, CA 92069-6515 US
    Email
    ramu.kallepalli@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps