Vibe Vulnerability Scanner
1 rating
)Overview
Scans web applications for security vulnerabilities
Catch exploitable vulnerabilities before attackers do. Vibe Vulnerability Scanner is a powerful Chrome extension that performs real-time security scanning of web applications using CISA's Known Exploited Vulnerabilities (KEV) catalog with automatic NVD verification. π KEY FEATURES β’ Real-time Scanning - Automatic vulnerability detection on page load β’ CISA KEV Integration - Checks against official Known Exploited Vulnerabilities catalog β’ NVD Verification - Confirms vulnerable versions using NIST CVE data β’ Persistent History - Stores last 50 scans per domain β’ Export Results - Download findings as JSON or CSV β’ HTTP Header Analysis - Inspects security headers β’ Confidence Scoring - Distinguishes confirmed findings from heuristics β’ Privacy First - All scanning happens locally, no data collection π‘οΈ WHAT GETS SCANNED Confirmed Issues: β HTTP Scripts - Loading scripts over insecure HTTP β Weak CSP - unsafe-inline or unsafe-eval in Content Security Policy β Vulnerable Libraries - Confirmed KEV match with NVD verification β Missing Security Headers - HSTS, X-Frame-Options, etc. Heuristic Patterns (Require Verification): β’ Inline Event Handlers - onclick, onerror, etc. β’ Secret Exposure - Pattern matching for API keys β’ innerHTML Usage - Potential XSS risk β’ Missing SRI - CDN scripts without integrity checks π UNDERSTANDING RESULTS Results are categorized by confidence level: β’ HIGH - Strong evidence (e.g., confirmed HTTP script loading) β’ MEDIUM - Likely issue requiring verification β’ LOW - Weak signal requiring manual investigation And by finding category: β’ Confirmed - Objective fact β’ Probable - Likely issue based on strong evidence β’ Heuristic - Pattern-based detection requiring context π SECURITY & PRIVACY β No External Data Transmission - All scanning is client-side β No User Tracking - No analytics, no telemetry β Minimal Permissions - Only activeTab, storage, alarms, tabs β Safe Rendering - All content rendered via DOM APIs β HTTPS Only - KEV catalog and NVD API calls use HTTPS β Open Source - Full source code available on GitHub π― PERFECT FOR β’ Security Professionals - Quick vulnerability assessment β’ Penetration Testers - Initial reconnaissance β’ Web Developers - Security hygiene checks during development β’ DevSecOps Teams - Shift-left security testing β’ Bug Bounty Hunters - Fast initial scanning π‘ HOW IT WORKS 1. Detects JavaScript libraries from script URLs and meta tags 2. Matches products against CISA KEV catalog 3. Fetches CVE details from NVD API for vulnerable version ranges 4. Compares detected versions to determine exposure 5. Provides actionable remediation guidance π GETTING STARTED 1. Install the extension 2. Navigate to any website 3. Click the extension icon 4. Review findings with severity breakdown 5. Expand details for remediation guidance 6. Export results if needed GitHub: https://github.com/ramukallepalli/vibe-vuln-scanner Documentation: https://github.com/ramukallepalli/vibe-vuln-scanner#readme Report Issues: https://github.com/ramukallepalli/vibe-vuln-scanner/issues Powered by CISA KEV and NIST NVD.
5 out of 51 rating
Details
- Version1.2.0
- UpdatedApril 29, 2026
- Offered byramu.kallepalli
- Size8.53MiB
- LanguagesEnglish (United States)
- DeveloperRamu Kallepalli
632 Allison Ln San Marcos, CA 92069-6515 USEmail
ramu.kallepalli@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes