YetAnotherBrowserExtension의 버전 기록 - 5개 버전
YetAnotherBrowserExtension 제작자: ONSEC
YetAnotherBrowserExtension의 버전 기록 - 5개 버전
이전 버전은 주의해서 사용하세요! 아래 버전들은 테스트 및 참조용으로만 제공됩니다.부가 기능은 항상 최신 버전으로 사용해 주세요.
최신 버전
버전 1.4
2026년 4월 20일에 출시 - 97.87 KBfirefox 126.0 이상에서 작동Release Notes - v1.4
Highlights
Major release expanding the extension from a basic secret scanner into
a full-featured security toolkit with severity classification, smart
validation, live key verification, and persistent false-positive
management.
New Features
Severity & Classification
- Severity levels for every finding: critical, high, medium, low, info.
- Color-coded severity badges with filtering in the Findings UI.
Active API Key Verification
- Live verification of detected keys via real HTTP requests.
- Supports 10 providers: Google, GitHub, GitLab, Slack, Stripe,
SendGrid, Telegram, npm, Cloudflare, and more.
- Automatic severity upgrade to "high" on confirmed-valid keys.
- Rate-limited to avoid provider throttling.
- Per-finding Verify button and status badges.
LLM-Based Validation
- OpenAI-compatible API integration for intelligent false-positive
detection.
- Configurable endpoint, model, and API key (stored securely).
- Auto-validate new findings or validate on demand (single / bulk).
- Connection test button in Settings.
Heuristic Pre-Filter
- Catches placeholder values, low-entropy strings, and documentation
examples before storing findings. Toggleable in Settings.
False-Positive Allowlist
- Persistent suppression of known false positives across re-scans.
- Per-origin or global scope.
- Manual mark as false-positive / confirmed from the Findings UI.
- Bulk delete, export, and import of the allowlist.
In-Tab Alerts
- Replaced OS notifications with in-tab JavaScript alerts.
- Configurable minimum severity threshold.
- 1-hour deduplication per origin.
AI / LLM Context File Scanning
- Active probes for AGENTS.md, CLAUDE.md, llms.txt, .cursor/, .claude/,
and other AI-related exposure points.
Detection Expansion- Pattern count: 35 -> 99 (95 secrets + 4 vulnerabilities).
- New providers: ElevenLabs, DeBounce, Square (prod and sandbox),
Discord (Bot token and Webhook), Cloudinary, Databricks, Instagram,
Contentful, Postman, Figma, Airtable, Flutterwave, Razorpay, HubSpot,
Pulumi, Age encryption keys, Artifactory, Branch.io, Sentry DSN, New
Relic, Algolia, Supabase (multiple key types), GitHub Fine-Grained
PAT, Google Service Account JSON, AWS Session Tokens, and DB
connection strings (MongoDB, PostgreSQL, Redis, MySQL). - Vulnerability detection skipped for JS files to reduce noise.
Improvements- Wildcard support in origin deny list at any position
(e.g. .domain.com, .gov., app.example.com). - .gov. added to the default deny list.
- Rescan disabled on extension and denied pages.
- Lazy pattern compilation for improved performance.
- Debug Mode page showing cached origins and live settings.
Fixes- Fixed browser notifications handling.
- Multiple stability and correctness improvements.
All Rights Reserved에 따라 릴리스된 소스 코드
이전 버전
버전 1.1.3
2026년 2월 4일에 출시 - 73.52 KBfirefox 126.0 이상에서 작동v1.1.3 - add Supabase Key detection and optional JWT detect toggleAll Rights Reserved에 따라 릴리스된 소스 코드
버전 1.1.2
2025년 12월 26일에 출시 - 73.34 KBfirefox 126.0 이상에서 작동- Improve JS file detection
- Fix popup showing "Scanning" when findings already exist
- Change default origin cache expiration: 1h → 24h
- Deduplication: Now uses type+match only
- Skip content script on about: and chrome: pages
- Fix popup for about: pages (origin returns "null" string)
- Add isSpecialPage() and isOriginInDenyList() helpers
All Rights Reserved에 따라 릴리스된 소스 코드
버전 1.1.0
2025년 12월 25일에 출시 - 70.55 KBfirefox 126.0 이상에서 작동• Added Debug Console for troubleshooting
• Reduced false positives on JavaScript files
• Improved scanning status feedback
• Fixed various UI bugsAll Rights Reserved에 따라 릴리스된 소스 코드
버전 1.0.0
2025년 11월 2일에 출시 - 68.07 KBfirefox 126.0 이상에서 작동All Rights Reserved에 따라 릴리스된 소스 코드