Tyre-Kicker-Security by Alex
The privacy-first security scanner. Instantly detect exposed API keys, Json Web tokens, CVEs, and common misconfiguration based vulnerabilities offline without your data ever leaving the browser.
Some features may require paymentSome features may require payment
Extension Metadata
Screenshots
About this extension
Tyre Kicker is the essential privacy-first security companion for your browser. It performs deep, offline analysis of any webpage to identify exposed secrets, outdated libraries, and critical misconfigurations—without single byte of data leaving your device.
🛡️ 100% Offline Privacy
Tested for internal tools and localhost. No external API calls. Your findings remain completely private.
🔑 Secret & Token Detection
Instantly flag exposed API keys (AWS, Stripe, Google), hardcoded credentials, and insecure JWTs hidden in source maps and minified bundles.
🐞 CVE Vulnerability Scanner
Automatically detects outdated frameworks (React, Angular, jQuery) and maps them to known CVEs using a local database.
📊 Graded Security Score
Get an immediate "Fort Knox" to "Wet Paper Bag" rating for any page, making risk assessment instant and visual.
📝 Professional Audit Reports
Export findings to PDF or JSON for compliance, client reports, or team sharing.
Built for:
- Bug Bounty Hunters
- Frontend Developers
- Security Auditors
Note: For authorized defensive security testing only.
🛡️ 100% Offline Privacy
Tested for internal tools and localhost. No external API calls. Your findings remain completely private.
🔑 Secret & Token Detection
Instantly flag exposed API keys (AWS, Stripe, Google), hardcoded credentials, and insecure JWTs hidden in source maps and minified bundles.
🐞 CVE Vulnerability Scanner
Automatically detects outdated frameworks (React, Angular, jQuery) and maps them to known CVEs using a local database.
📊 Graded Security Score
Get an immediate "Fort Knox" to "Wet Paper Bag" rating for any page, making risk assessment instant and visual.
📝 Professional Audit Reports
Export findings to PDF or JSON for compliance, client reports, or team sharing.
Built for:
- Bug Bounty Hunters
- Frontend Developers
- Security Auditors
Note: For authorized defensive security testing only.
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Access your data for all web sites
Optional permissions:
- Access your data for all web sites
Required data collection, according to the developer:
- Authentication information
Optional data collection, according to the developer:
- Technical and interaction data
More information
- Add-on Links
- Version
- 0.0.51
- Size
- 1.8 MB
- Last updated
- 4 days ago (19 Dec 2025)
- Related Categories
- Licence
- All Rights Reserved
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Tags
- Add to collection