Advanced Client-Side Prototype Pollution Scanner
-
Updated
Sep 28, 2026 - Go
Advanced Client-Side Prototype Pollution Scanner
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified
Secure your code in seconds. VibeSafe is an AI-native DevSecOps CLI tool that detects vulnerabilities, secrets, insecure configs, and hallucinated dependencies before they ship.
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
A client-side web security tool that sanitizes potentially malicious HTML and JavaScript input by stripping unsafe tags and event attributes. Designed to demonstrate XSS prevention concepts, safe input handling, and frontend security practices using pure HTML, CSS, and JavaScript in a beginner-friendly interface.
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks, helping make your website resistant to SSRF attacks when implemented correctly.
Rust CLI and GitHub Action for static supply-chain scanning across eight package ecosystems, lockfiles, and coding-agent configuration.
JavaScript Security Engineering (Helicopter View) workshop, crafted for 3 hours with a bunch of demos
JavaScript Intelligence Engine - SPA bundle'larindan secret/endpoint/source-map cikartan tek dosya ofansif recon araci. 63 secret regex'i, Source Map V3 dekoderi, webpack chunk parser, multi-format cikti. Bug bounty + self-audit.
Find subdomains and urls in Javascript files
ScriptSentry is an advanced JavaScript security scanner designed to detect exposed secrets, vulnerabilities, and sensitive data in JavaScript files. It automatically crawls websites to discover JS files and scans them
Scan and fix vulnerabilities in Python, JavaScript, TypeScript, Go, and Java code using AI-powered analysis with 200 built-in security rules.
Guide intended for full-stack developers to secure projects with JavaScript technologies (React, Vue, etc.) and a Node.js/PHP backend with CRUD/REST APIs
A new package that analyzes user-provided JavaScript code snippets to determine if they can run concurrently without conflicts or race conditions. It takes the code as text input and returns a structu
2026 research guide covering ChatGPT Pro and Plus regional price reports, Egypt and Philippines billing claims, browser-console script risks, card anecdotes, renewal comparisons, payment troubleshooting, and official account safety.
AstraJS is a fast and powerful CLI-based JavaScript security analyzer that scans websites for hidden endpoints, exposed credentials, and sensitive data. It helps security researchers identify potential vulnerabilities through automated extraction, network intelligence, and detailed JSON reporting.
🔍 AI-Powered JavaScript Vulnerability Scanner & Security Automation Tool | Detect XSS, code injection, secrets & more using Google Gemini AI | Multi-purpose security engine with customizable YAML templates for penetration testing & red team operations
Secure your code in seconds. VibeSafe is an AI-native DevSecOps CLI tool that detects vulnerabilities, secrets, insecure configs, and hallucinated dependencies before they ship.
To associate your repository with the javascript-security topic, visit your repo's landing page and select "manage topics."