
JS Recon Buddy by JSReconBuddy
A simple browser extension to quickly find interesting security-related information on a webpage.
5 Users5 Users
Extension Metadata
Screenshots



About this extension
The scanner uses a set of regex patterns to identify and categorize potential security-related information:
- Subdomains - discovers related subdomains within the code.
- Endpoints & Paths - uncovers potential API endpoints and other useful paths.
- Potential Secrets - scans for API keys, tokens, and other sensitive data using pattern matching and Shannon entropy checks.
- Potential DOM XSS Sinks - identifies dangerous properties and functions like .innerHTML and document.write.
- Interesting Parameters - flags potentially vulnerable URL parameters (e.g., redirect, debug, url).
- Source Maps - finds links to source maps which can expose original source code.
If it is a valid source map, the extension tries to deconstruct source files based on data there
- JS Libraries - lists identified JavaScript libraries and their versions.
Rated 0 by 0 reviewers
Permissions and dataLearn more
Required permissions:
- Access browser tabs
- Access browser activity during navigation
Optional permissions:
- Access your data for all websites
More information
- Add-on Links
- Version
- 1.12.1
- Size
- 526.41 KB
- Last updated
- 8 hours ago (Oct 7, 2025)
- Related Categories
- License
- MIT License
- Version History
- Tags
- Add to collection