Advanced Client-Side Prototype Pollution Scanner
-
Updated
Oct 2, 2026 - Go
Advanced Client-Side Prototype Pollution Scanner
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified
Secure your code in seconds. VibeSafe is an AI-native DevSecOps CLI tool that detects vulnerabilities, secrets, insecure configs, and hallucinated dependencies before they ship.
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks, helping make your website resistant to SSRF attacks when implemented correctly.
A client-side web security tool that sanitizes potentially malicious HTML and JavaScript input by stripping unsafe tags and event attributes. Designed to demonstrate XSS prevention concepts, safe input handling, and frontend security practices using pure HTML, CSS, and JavaScript in a beginner-friendly interface.
Rust CLI and GitHub Action for static supply-chain scanning across eight package ecosystems, lockfiles, and coding-agent configuration.
JavaScript Security Engineering (Helicopter View) workshop, crafted for 3 hours with a bunch of demos
JavaScript Intelligence Engine - SPA bundle'larindan secret/endpoint/source-map cikartan tek dosya ofansif recon araci. 63 secret regex'i, Source Map V3 dekoderi, webpack chunk parser, multi-format cikti. Bug bounty + self-audit.
Find subdomains and urls in Javascript files
ScriptSentry is an advanced JavaScript security scanner designed to detect exposed secrets, vulnerabilities, and sensitive data in JavaScript files. It automatically crawls websites to discover JS files and scans them
Guide intended for full-stack developers to secure projects with JavaScript technologies (React, Vue, etc.) and a Node.js/PHP backend with CRUD/REST APIs
Scan and fix vulnerabilities in Python, JavaScript, TypeScript, Go, and Java code using AI-powered analysis with 200 built-in security rules.
A new package that analyzes user-provided JavaScript code snippets to determine if they can run concurrently without conflicts or race conditions. It takes the code as text input and returns a structu
AstraJS is a fast and powerful CLI-based JavaScript security analyzer that scans websites for hidden endpoints, exposed credentials, and sensitive data. It helps security researchers identify potential vulnerabilities through automated extraction, network intelligence, and detailed JSON reporting.
2026 research guide covering ChatGPT Pro and Plus regional price reports, Egypt and Philippines billing claims, browser-console script risks, card anecdotes, renewal comparisons, payment troubleshooting, and official account safety.
🔍 AI-Powered JavaScript Vulnerability Scanner & Security Automation Tool | Detect XSS, code injection, secrets & more using Google Gemini AI | Multi-purpose security engine with customizable YAML templates for penetration testing & red team operations
Chrome extension (Manifest V3) that grades the security of the page you're on, A to F: TLS certificate, security headers, cookies, API calls, hardcoded secrets and vulnerable JS libraries. 100% local, no telemetry, zero dependencies.
To associate your repository with the javascript-security topic, visit your repo's landing page and select "manage topics."