DOM Input Liberator por Lamisedaxeh
Pentesting tool: remove form restrictions, reveal hidden elements, bypass input validation
Metadados da extensão
Capturas de ecrã
Acerca desta extensão
A browser extension for penetration testing that removes client-side form restrictions, reveals hidden elements, and bypasses input validation. Works on Chrome and Firefox.
UI:
Features list:
UI:
- Popup — Toggle categories on/off individually or use "Liberate All" master toggle. Each category can be expanded to enable/disable specific items.
- Floating Badge — A counter badge appears on the page showing how many elements were modified. Click it to see a per-category breakdown. Click outside to dismiss.
- Highlighting — Modified elements are outlined in the category's color. Toggle highlighting on/off from the popup.
Features list:
- Form Controls: Remove
disabled,readonly,required,maxlength,minlength,pattern,multiple,acceptattributes, re-enableautocomplete, reveal password fields as plain text - Input Validation: Strip
min,max,stepattributes and convert restricted input types (number, email, url, date, etc.) to plain text fields - Hidden Fields: Convert
type="hidden"inputs to visible text fields with a purple dashed border so you can view and edit their values - Hidden Elements (CSS): Reveal elements hidden via
display: none,visibility: hidden,opacity: 0, thehiddenattribute, or collapsed<details>elements - Content Editing: Make all block-level elements contenteditable so you can modify any text on the page. Disabled by default
- Iframes: Reveal hidden iframes (zero-sized, display:none, opacity:0) with a labeled border showing their
src - Event Blockers: Remove inline event handlers that block user interaction:
onsubmit,onchange,oninput,oncopy,onpaste,oncut. Also prevents clipboard and context menu blocking - Size Constraints: Remove
cols,rows,sizeattributes from textareas/inputs and forceresize: bothon textareas - Comments: Unwrap HTML comments so their content becomes live DOM. Uncomment JS comments in inline scripts so commented-out code executes
- Fill Payloads: One-click button to fill all visible inputs with XSS, template injection, SQL injection, and path traversal test payloads
This tool is intended for authorized security testing and bug bounty programs. Only use it on applications you have permission to test.
Rated 0 by 0 reviewers
Permissions and data
Permissões necessárias:
- Aceder aos seus dados para todos os sites
Data collection:
- The developer says this extension doesn't require data collection.
Mais informação
- Ligações do complemento
- Versão
- 1.0.0
- Tamanho
- 41,26 KB
- Última atualização
- há 14 dias (10 de jul de 2026)
- Categorias relacionadas
- Histórico de versões
- Adicionar à coleção