Skip to main content
SecuriScan - Web Security Analyzer icon

SecuriScan - Web Security Analyzer

SecuriScan is a powerful Chrome extension that performs comprehensive passive security analysis on any website. Built for developers, security professionals, and anyone who wants quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. šŸ†• š—Ŗš—›š—”š—§'š—¦ š—”š—˜š—Ŗ š—œš—” š—©šŸ­.šŸ°.šŸ¬ • šŸ›” OWASP Top 10 view — maps every finding to the OWASP Top 10 (2021) with PASS/WARN/FAIL badges • šŸ¤– AI Explain & Fix — one-click explanations and copy-paste code fixes for every vulnerability found • šŸ“Š Side Panel mode — persistent scanning panel that stays open alongside your browsing (Alt+Shift+P) • šŸ”¢ Toolbar badge — live issue count on the extension icon, colour-coded by severity • šŸ“” Network security scan — detects insecure WebSockets (ws://), WebRTC IP leakage, unsafe postMessage usage, hardcoded private IPs, and dynamic script injection • āš™ SARIF 2.1.0 export — export results in industry-standard SARIF format for CI/CD pipeline integration • ⌨ Keyboard shortcuts — Alt+Shift+S to scan, Alt+Shift+P to open the side panel • šŸ–± Right-click context menu — scan any page directly from the right-click menu • āš™ Settings tab — toggle auto-scan (opt-in, off by default), desktop notifications, and badge display • šŸ“ˆ Score sparklines — visual score history chart per domain in the History tab šŸ†• š—Ŗš—›š—”š—§'š—¦ š—”š—˜š—Ŗ š—œš—” š—©šŸ­.šŸÆ.šŸ¬ • šŸ‘ Privacy tracker detection — flags 18 third-party trackers including Meta Pixel, TikTok, Hotjar, FullStory, and more • šŸ’¾ Browser storage audit — scans localStorage and sessionStorage for exposed tokens, keys, and PII • šŸ“ˆ Scan history & score trends — tracks your last 10 scans per domain and shows ↑/↓ trend on every result • šŸ“„ JSON export — export results as machine-readable JSON alongside the existing HTML report šŸ” š—Ŗš—›š—”š—§ š—œš—§ š——š—¢š—˜š—¦ When you click scan, SecuriScan analyzes the current page for security misconfigurations and vulnerabilities across 13 categories: šŸ”’ š—¦š—²š—°š˜‚š—æš—¶š˜š˜† š—›š—²š—®š—±š—²š—æš˜€ (šŸ­šŸ¬ š—°š—µš—²š—°š—øš˜€) • Content-Security-Policy (CSP) • Strict-Transport-Security (HSTS) • X-Frame-Options • X-Content-Type-Options • Referrer-Policy • Permissions-Policy • Cross-Origin-Opener-Policy • Cross-Origin-Resource-Policy • Cross-Origin-Embedder-Policy • X-XSS-Protection šŸŖ š—–š—¼š—¼š—øš—¶š—² š—¦š—²š—°š˜‚š—æš—¶š˜š˜† • HttpOnly and Secure flag validation • Session token exposure detection • Sensitive cookie pattern matching • SameSite attribute guidance šŸ“š š—©š˜‚š—¹š—»š—²š—æš—®š—Æš—¹š—² š—š—®š˜ƒš—®š—¦š—°š—æš—¶š—½š˜ š—Ÿš—¶š—Æš—æš—®š—æš—¶š—²š˜€ (šŸÆšŸ±+ š—¹š—¶š—Æš—æš—®š—æš—¶š—²š˜€) šŸ”“ Critical Severity: • Handlebars < 4.7.7 (arbitrary code execution) • Socket.IO < 4.4.1 (CORS bypass) • Minimist < 1.2.6 (prototype pollution) • EJS < 3.1.7 (template injection) 🟠 High Severity: • jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) • AngularJS < 1.8.3 (CVE-2023-26116) • Lodash < 4.17.21 (CVE-2021-23337, CVE-2020-28500) • React < 16.14.0 (CVE-2021-23648) • Vue.js < 2.6.14 (CVE-2021-3766) • Marked < 4.0.10 (ReDoS and XSS) • DOMPurify < 2.3.10 (XSS bypass) • Express < 4.17.3 (open redirect) • Webpack < 5.76.0 (cross-realm access) • Underscore < 1.13.0 (code execution) • Next.js < 12.3.2 (open redirect) • Nuxt.js < 2.15.7 (directory traversal) • Pug < 3.0.1 (code injection) 🟔 Medium Severity: • Bootstrap < 4.3.1 (CVE-2019-8331) • Moment.js < 2.29.4 (CVE-2022-31129) • Axios < 0.21.3 (SSRF) • D3.js, Chart.js, DataTables, and more šŸ” š—¦š—²š—»š˜€š—¶š˜š—¶š˜ƒš—² š——š—®š˜š—® š—˜š˜…š—½š—¼š˜€š˜‚š—æš—² (šŸ®šŸ±+ š—½š—®š˜š˜š—²š—æš—»š˜€) šŸ— API Keys & Tokens: • AWS Access/Secret Keys • Google API Keys & OAuth • GitHub Personal Access Tokens • Stripe API Keys (live & test) • Slack Tokens • Twilio, SendGrid, Mailgun API Keys • PayPal Braintree Tokens • Square OAuth Secrets • Shopify Access Tokens & Shared Secrets • Generic API key patterns šŸ”‘ Credentials & Secrets: • Private Keys (RSA, SSH, EC, PGP, OpenSSH) • Database Connection Strings (MongoDB, MySQL, PostgreSQL) • JWT Tokens • Passwords in source code • Firebase URLs 🪪 PII: • Credit Card Patterns • Social Security Numbers • Email Addresses (filtered for false positives) šŸ‘ š—£š—æš—¶š˜ƒš—®š—°š˜† š—§š—æš—®š—°š—øš—²š—æš˜€ Detects 18 third-party tracking scripts that collect and share your users' behavioral data: • šŸŽ„ Session recorders: Hotjar, FullStory, Mouseflow, Crazy Egg • šŸ“¢ Ad pixels: Meta/Facebook, TikTok, Twitter/X, LinkedIn Insight • šŸ“Š Analytics: Google Analytics, Google Tag Manager, Mixpanel, Amplitude, Heap, Clarity • šŸ’¬ CRM: HubSpot, Intercom, Pardot, Segment Each tracker is rated by severity — session recorders (high) vs. analytics-only (medium) — so you know which ones are most invasive. šŸ’¾ š—•š—æš—¼š˜„š˜€š—²š—æ š—¦š˜š—¼š—æš—®š—“š—² š—”š˜‚š—±š—¶š˜ Scans localStorage and sessionStorage for sensitive data that XSS could steal: • Auth tokens, JWT, session IDs stored under sensitive key names • API keys, AWS credentials, private keys in stored values • Credit card numbers and SSNs • Flags risky storage patterns and recommends HttpOnly cookies instead šŸ“” š—”š—²š˜š˜„š—¼š—æš—ø š—¦š—²š—°š˜‚š—æš—¶š˜š˜† (š—”š—˜š—Ŗ š—¶š—» š˜ƒšŸ­.šŸ°.šŸ¬) Passively inspects inline scripts for risky network patterns: • Insecure WebSocket connections using ws:// instead of wss:// • WebRTC usage that can leak real IP addresses through VPNs • postMessage() calls without event.origin validation • Hardcoded private/internal IP addresses (192.168.x, 10.x, 127.0.0.1) • Dynamic <script> element injection • Hardcoded cross-origin fetch endpoints āš ļø š—–š—¼š—ŗš—ŗš—¼š—» š—©š˜‚š—¹š—»š—²š—æš—®š—Æš—¶š—¹š—¶š˜š—¶š—²š˜€ • Mixed content detection (HTTP resources on HTTPS pages) • Forms submitting over insecure connections • Missing CSRF token detection • Password fields on non-HTTPS pages • Credit card/SSN fields without HTTPS • Inline event handlers (onclick, onload, etc.) • JavaScript URLs and data: URLs • eval() and dangerous DOM manipulation • Exposed API keys and credentials in source šŸ›” š—”š—±š—±š—¶š˜š—¶š—¼š—»š—®š—¹ š—¦š—²š—°š˜‚š—æš—¶š˜š˜† š—–š—µš—²š—°š—øš˜€ • Subresource Integrity (SRI) validation for CDN resources • CORS configuration analysis • Enhanced XSS detection with 10+ event handler types • srcdoc attribute usage in iframes • URL manipulation pattern detection āš™ļø š—›š—¢š—Ŗ š—œš—§ š—Ŗš—¢š—„š—žš—¦ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against a comprehensive vulnerability database with CVE tracking. No data leaves your machine. Results are presented with a 0–100 security score using severity-based weighting (Critical/High/Medium/Low). A trend indicator (↑/↓/→) shows how the score changed since your last scan of that domain. The OWASP tab maps every finding to the OWASP Top 10 (2021) so you can communicate risk in a language your team understands. Click any category to see specific findings with remediation guidance and CVE references. Every vulnerability includes a šŸ¤– Explain & Fix button with a plain-English explanation and a copy-paste code fix. Export as a formatted HTML report, machine-readable JSON, or SARIF 2.1.0 for CI/CD pipelines and client deliverables. šŸ‘„ š—Ŗš—›š—¢ š—œš—§'š—¦ š—™š—¢š—„ • šŸ‘Øā€šŸ’» Frontend developers checking sites before deployment • šŸ” Security engineers doing quick reconnaissance • šŸš€ DevOps teams validating production configurations • šŸŽÆ Penetration testers performing initial assessments • šŸ’¼ Freelancers auditing client websites • šŸŽ“ Students learning web security fundamentals • 🌐 Anyone concerned about website security šŸ”§ š—§š—˜š—–š—›š—”š—œš—–š—”š—Ÿ š——š—˜š—§š—”š—œš—Ÿš—¦ Built on Manifest V3 with minimal permissions: • activeTab — access current page when you click scan • scripting — inject analysis code into the page • storage — cache scan results and history locally • tabs — read current tab URL for history tracking • sidePanel — enable the persistent side panel (v1.4.0) • contextMenus — add right-click scan option (v1.4.0) • notifications — optional alerts for critical findings (v1.4.0, opt-in) ✨ New in v1.4.0: • OWASP Top 10 (2021) compliance view • AI-powered Explain & Fix for every finding • Persistent side panel mode • Toolbar badge with live issue count • Network & API security scanning • SARIF 2.1.0 export • Keyboard shortcuts (Alt+Shift+S / Alt+Shift+P) • Right-click context menu integration • Configurable auto-scan (opt-in, off by default) • Settings tab with notification and badge controls No telemetry. No external API calls. The entire codebase is open source if you want to audit it or contribute. 🚫 š—Ÿš—œš— š—œš—§š—”š—§š—œš—¢š—”š—¦ This is a passive scanner, not a penetration testing tool. It cannot: • Test for server-side vulnerabilities (SQLi, SSRF, RCE, etc.) • Intercept or modify HTTP traffic • Perform authenticated scanning • Detect all possible security issues • Replace a proper security audit by professionals Think of it as a comprehensive health check and reconnaissance tool, not a replacement for professional security testing. šŸ•µļø š—£š—„š—œš—©š—”š—–š—¬ Zero data collection. No analytics. No tracking. No external servers. Everything stays on your device. Built by developers, for developers. No fluff, just useful security insights with real CVE tracking, OWASP mapping, and actionable remediation guidance.

Bilder im Chrome Web Store

Discovery