Item logo image for WebSurgeon

WebSurgeon

Item media 6 (screenshot) for WebSurgeon
Item video thumbnail
Item media 2 (screenshot) for WebSurgeon
Item media 3 (screenshot) for WebSurgeon
Item media 4 (screenshot) for WebSurgeon
Item media 5 (screenshot) for WebSurgeon
Item media 6 (screenshot) for WebSurgeon
Item video thumbnail
Item video thumbnail
Item media 2 (screenshot) for WebSurgeon
Item media 3 (screenshot) for WebSurgeon
Item media 4 (screenshot) for WebSurgeon
Item media 5 (screenshot) for WebSurgeon
Item media 6 (screenshot) for WebSurgeon

Overview

Advanced network inspection with request highlighting, color tagging, request repeating, passive scanner for JS files and retirejs

WebSurgeon is a powerful browser-native security toolkit for web application testers, bug bounty hunters, and developers who need deep visibility into HTTP traffic — without leaving the browser. 🔍 ADVANCED NETWORK INSPECTION Go beyond DevTools. Capture, filter, and analyze every request with a high-signal interface designed for security workflows. Spot anomalies fast with color-coded request tagging and real-time highlighting. 🏷️ REQUEST HIGHLIGHTING & COLOR TAGGING Visually organize traffic by marking requests with custom color tags. Track interesting endpoints, flag suspicious patterns, and keep your testing sessions organized across complex applications. 🔁 REQUEST REPEATING Resend any captured request with a single click — no need to trigger the original action again. Tweak parameters, headers, or payloads on the fly for quick manual testing. 🛡️ PASSIVE JAVASCRIPT SCANNER Automatically analyzes JavaScript files loaded by the page for hardcoded secrets, API keys, sensitive strings, and security misconfigurations — passively, with no active probing required. 📦 RETIREJS INTEGRATION Detects outdated and vulnerable JavaScript libraries using the RetireJS vulnerability database. Know instantly when a page relies on a component with a known CVE. 🔗 LINK FINDER Extracts all URLs, endpoints, and paths discovered within JS files and page source — surfacing hidden API routes, internal paths, and forgotten endpoints that standard crawlers miss. --- WHO IS THIS FOR? • Bug bounty hunters doing recon and passive analysis • Penetration testers performing web application assessments • Security engineers auditing third-party JS dependencies • Developers checking their own apps for accidental exposure --- PRIVACY & PERMISSIONS WebSurgeon only inspects traffic in the active tab when you choose to run it. No data is sent to external servers. All analysis happens locally in your browser.

Details

  • Version
    0.0.2
  • Updated
    May 8, 2026
  • Offered by
    MrGreen
  • Size
    63.45KiB
  • Languages
    English
  • Developer
    Email
    boody201010@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

RequestScope

5.0

Monitor network requests and API failures with real-time insights

DotDrop - Sensitive File Detector

0.0

Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.

Inssman: Open-Source: Modify HTTP Request

4.1

Intercept HTTP(S) Request, Modify Headers, Log headers, Change Response, Block Request, Redirect, Custom HTML/CSS/JS/JSON

Unused CSS/JS Detector

3.5

Detects unused CSS and JS files on web pages

API Sniffer - Endpoint Detector

5.0

Capture, replay, and automate HTTP requests with real-time WebSocket, WebRTC monitoring and passive API leak detection.

CyberPost Lab

5.0

A fully offline, browser-based HTTP request testing tool for cybersecurity researchers

Design System Extractor

0.0

Extract a complete design system from any website — colors, typography, spacing, shadows, and more

SecretSifter: Live Credentials & Secrets Scanner

5.0

Detects secrets, API keys, and tokens in JS, JSON, XML, and HTML at runtime

Mock Express - Modify, Mock & Intercept HTTP Requests Locally

5.0

Intercept, mock, and modify API requests directly in your browser. No server needed. 100% local and secure.

Network Investigator

0.0

Advanced network traffic analysis tool for developers. Inspect HTTP requests with enhanced search and filtering capabilities.

Network Ninja

5.0

Enhanced network request inspection with secure curl generation for Chrome DevTools

VulnCheck Insights

5.0

Lookup CVEs, CPEs, and PURLs with VulnCheck

RequestScope

5.0

Monitor network requests and API failures with real-time insights

DotDrop - Sensitive File Detector

0.0

Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.

Inssman: Open-Source: Modify HTTP Request

4.1

Intercept HTTP(S) Request, Modify Headers, Log headers, Change Response, Block Request, Redirect, Custom HTML/CSS/JS/JSON

Unused CSS/JS Detector

3.5

Detects unused CSS and JS files on web pages

API Sniffer - Endpoint Detector

5.0

Capture, replay, and automate HTTP requests with real-time WebSocket, WebRTC monitoring and passive API leak detection.

CyberPost Lab

5.0

A fully offline, browser-based HTTP request testing tool for cybersecurity researchers

Design System Extractor

0.0

Extract a complete design system from any website — colors, typography, spacing, shadows, and more

SecretSifter: Live Credentials & Secrets Scanner

5.0

Detects secrets, API keys, and tokens in JS, JSON, XML, and HTML at runtime

Google apps