Item logo image for Vibe Vulnerability Scanner

Vibe Vulnerability Scanner

5.0(

1 rating

)
ExtensionDeveloper Tools24 users
Item media 4 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 2 (screenshot) for Vibe Vulnerability Scanner
Item media 3 (screenshot) for Vibe Vulnerability Scanner
Item media 4 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 1 (screenshot) for Vibe Vulnerability Scanner
Item media 2 (screenshot) for Vibe Vulnerability Scanner
Item media 3 (screenshot) for Vibe Vulnerability Scanner
Item media 4 (screenshot) for Vibe Vulnerability Scanner

Overview

Scans web applications for security vulnerabilities

Catch exploitable vulnerabilities before attackers do. Vibe Vulnerability Scanner is a powerful Chrome extension that performs real-time security scanning of web applications using CISA's Known Exploited Vulnerabilities (KEV) catalog with automatic NVD verification. πŸ” KEY FEATURES β€’ Real-time Scanning - Automatic vulnerability detection on page load β€’ CISA KEV Integration - Checks against official Known Exploited Vulnerabilities catalog β€’ NVD Verification - Confirms vulnerable versions using NIST CVE data β€’ Persistent History - Stores last 50 scans per domain β€’ Export Results - Download findings as JSON or CSV β€’ HTTP Header Analysis - Inspects security headers β€’ Confidence Scoring - Distinguishes confirmed findings from heuristics β€’ Privacy First - All scanning happens locally, no data collection πŸ›‘οΈ WHAT GETS SCANNED Confirmed Issues: βœ“ HTTP Scripts - Loading scripts over insecure HTTP βœ“ Weak CSP - unsafe-inline or unsafe-eval in Content Security Policy βœ“ Vulnerable Libraries - Confirmed KEV match with NVD verification βœ“ Missing Security Headers - HSTS, X-Frame-Options, etc. Heuristic Patterns (Require Verification): β€’ Inline Event Handlers - onclick, onerror, etc. β€’ Secret Exposure - Pattern matching for API keys β€’ innerHTML Usage - Potential XSS risk β€’ Missing SRI - CDN scripts without integrity checks πŸ“Š UNDERSTANDING RESULTS Results are categorized by confidence level: β€’ HIGH - Strong evidence (e.g., confirmed HTTP script loading) β€’ MEDIUM - Likely issue requiring verification β€’ LOW - Weak signal requiring manual investigation And by finding category: β€’ Confirmed - Objective fact β€’ Probable - Likely issue based on strong evidence β€’ Heuristic - Pattern-based detection requiring context πŸ”’ SECURITY & PRIVACY βœ“ No External Data Transmission - All scanning is client-side βœ“ No User Tracking - No analytics, no telemetry βœ“ Minimal Permissions - Only activeTab, storage, alarms, tabs βœ“ Safe Rendering - All content rendered via DOM APIs βœ“ HTTPS Only - KEV catalog and NVD API calls use HTTPS βœ“ Open Source - Full source code available on GitHub 🎯 PERFECT FOR β€’ Security Professionals - Quick vulnerability assessment β€’ Penetration Testers - Initial reconnaissance β€’ Web Developers - Security hygiene checks during development β€’ DevSecOps Teams - Shift-left security testing β€’ Bug Bounty Hunters - Fast initial scanning πŸ’‘ HOW IT WORKS 1. Detects JavaScript libraries from script URLs and meta tags 2. Matches products against CISA KEV catalog 3. Fetches CVE details from NVD API for vulnerable version ranges 4. Compares detected versions to determine exposure 5. Provides actionable remediation guidance πŸš€ GETTING STARTED 1. Install the extension 2. Navigate to any website 3. Click the extension icon 4. Review findings with severity breakdown 5. Expand details for remediation guidance 6. Export results if needed GitHub: https://github.com/ramukallepalli/vibe-vuln-scanner Documentation: https://github.com/ramukallepalli/vibe-vuln-scanner#readme Report Issues: https://github.com/ramukallepalli/vibe-vuln-scanner/issues Powered by CISA KEV and NIST NVD.

Details

  • Version
    1.2.0
  • Updated
    April 29, 2026
  • Offered by
    ramu.kallepalli
  • Size
    8.53MiB
  • Languages
    English (United States)
  • Developer
    Ramu Kallepalli
    632 Allison Ln San Marcos, CA 92069-6515 US
    Email
    ramu.kallepalli@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps