Item logo image for API Call Detector

API Call Detector

5.0 (

2 ratings

)
Extension Tools 128 users
Item media 2 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 2 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 1 (screenshot) for API Call Detector
Item media 2 (screenshot) for API Call Detector

Overview

Security tool to actively detect external API calls made from displayed web page

API Call Detector - Cybersecurity Analysis Tool Identify potential security risks by mapping all external API calls made through JavaScript. This professional-grade extension provides real-time monitoring of web page communications, helping security teams uncover hidden data flows, unauthorized third-party integrations, and potential attack vectors. Key Features: Real-time detection of XMLHttpRequest, Fetch API, and WebSocket connections Automatic filtering of static resources (images/CSS/fonts) Security-focused reporting with domain frequency analysis Exportable audit trails in markdown format Cross-origin call tracking with full URL capture Manifest V3 compliant with strict CSP policies Ideal For: Identifying shadow APIs in enterprise web applications Auditing data flows for GDPR/HIPAA compliance Detecting unauthorized third-party trackers Educational white-hat hacking exercises Penetration testing reconnaissance phases Monitoring client-side supply chain risks Technical Specifications: Operates at document_start phase to capture initializations Content script injection via Chrome extension APIs Background service worker maintains isolated call registry Secure message passing between components Zero data collection/telemetry Use Cases: Vulnerability Assessment: Map all external endpoints contacted during user sessions Incident Response: Quickly identify compromised APIs during breach investigations Third-Party Audit: Document data leakage points to external services Developer Education: Visualize runtime network behavior of SPAs Compliance Reporting: Generate evidence of endpoint security checks Advanced Capabilities: Path-based sorting and domain clustering Automatic deduplication of repeated calls Query parameter stripping for clean analysis Multi-frame tracking (iframes/web workers) Detection bypass prevention through prototype hooks For Security Teams: Prioritize endpoints by call frequency Spot anomalous domains in real-time Export findings to standard threat intelligence formats Integrate with SIEM systems via manual export Development Philosophy: Minimal permissions required (storage, downloads, webNavigation) No background page persistence Strict content security policy enforcement Regular updates to match evolving web standards Open Source Ready: Clean codebase for organizational customization MIT License (contact developer for enterprise terms) Built for extensibility (add custom filters/hooks) Install to gain immediate visibility into client-side network activity and strengthen your organization's web application security posture. Essential for modern cybersecurity defense-in-depth strategies.

Details

  • Version
    1.0
  • Updated
    March 18, 2025
  • Size
    53.75KiB
  • Languages
    English
  • Developer
    Geekus Maximus
    39 N Main St New Castle, KY 40050 US
    Website
    Email
    docdaven@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy .

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

API Call Recorder

0.0

Record and analyze API calls directly from your browser.

JWT Sniffer

5.0

Catch and decode all the JWTs

JSner - Endpoint Extractor

0.0

Advanced endpoint scanner with verification. Extract and test API endpoints, GraphQL queries, and more from any website.

Hidden APIs

0.0

Find & inspect internal APIs, scrape & automate tasks with ease. Ideal for devs, data scientists & web enthusiasts.

Pathprobe

5.0

Asychronous multi-domain directory scanner

Detector APIs Extension

5.0

The extension supports getting all APIs and CURL command when load a website.

Fetch Log - API Inspector

0.0

Monitor and inspect fetch/XHR network requests with a clean developer UI

API Monitor

5.0

Show active intervals, scheduled timeouts, animation frames, idle callbacks, eval invocations, media, workers, scheduler API

API Sniffer

0.0

方便追蹤API回傳的JSON內容的工具

API Response Viewer

1.0

Captures, formats, and displays API responses in a clean interface for easy debugging and analysis of web applications.

API Sniffer - Endpoint Detector

4.5

A developer tool to debug and analyze API calls for testing.

JSX - JavaScript Explorer

0.0

Finds all JavaScript files, form endpoints, and links on the current webpage.

API Call Recorder

0.0

Record and analyze API calls directly from your browser.

JWT Sniffer

5.0

Catch and decode all the JWTs

JSner - Endpoint Extractor

0.0

Advanced endpoint scanner with verification. Extract and test API endpoints, GraphQL queries, and more from any website.

Hidden APIs

0.0

Find & inspect internal APIs, scrape & automate tasks with ease. Ideal for devs, data scientists & web enthusiasts.

Pathprobe

5.0

Asychronous multi-domain directory scanner

Detector APIs Extension

5.0

The extension supports getting all APIs and CURL command when load a website.

Fetch Log - API Inspector

0.0

Monitor and inspect fetch/XHR network requests with a clean developer UI

API Monitor

5.0

Show active intervals, scheduled timeouts, animation frames, idle callbacks, eval invocations, media, workers, scheduler API

Google apps
Create a Mobile Website
View Site in Mobile | Classic
Share by: