Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
-
Updated
Jul 19, 2026 - Python
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Find subdomains and urls in Javascript files
JavaScript Intelligence Engine - SPA bundle'larindan secret/endpoint/source-map cikartan tek dosya ofansif recon araci. 63 secret regex'i, Source Map V3 dekoderi, webpack chunk parser, multi-format cikti. Bug bounty + self-audit.
ScriptSentry is an advanced JavaScript security scanner designed to detect exposed secrets, vulnerabilities, and sensitive data in JavaScript files. It automatically crawls websites to discover JS files and scans them
A new package that analyzes user-provided JavaScript code snippets to determine if they can run concurrently without conflicts or race conditions. It takes the code as text input and returns a structu
🔍 AI-Powered JavaScript Vulnerability Scanner & Security Automation Tool | Detect XSS, code injection, secrets & more using Google Gemini AI | Multi-purpose security engine with customizable YAML templates for penetration testing & red team operations
Next.js JS bundle API endpoint discovery tool — no wordlists, real browser interception
JS Bundle Credential Hunter — finds hardcoded admin credentials in AI-generated websites (Next.js, Vite, React). Security research tool by @ethicalcodnoz
AstraJS is a fast and powerful CLI-based JavaScript security analyzer that scans websites for hidden endpoints, exposed credentials, and sensitive data. It helps security researchers identify potential vulnerabilities through automated extraction, network intelligence, and detailed JSON reporting.
Add a description, image, and links to the javascript-security topic page so that developers can more easily learn about it.
To associate your repository with the javascript-security topic, visit your repo's landing page and select "manage topics."