Item logo image for LPR - Ultimate Recon & Bug Hunting Tool

LPR - Ultimate Recon & Bug Hunting Tool

5.0 (

4 ratings

)
Item media 1 (screenshot) for LPR - Ultimate Recon & Bug Hunting Tool

Overview

Stop manually searching source code. Start hunting. LPR (Live Params & Redirects) is an all-in-one reconnaissance and…

Stop manually searching source code. Start hunting. LPR (Live Params & Redirects) is an all-in-one reconnaissance and vulnerability scanning assistant designed for Bug Bounty Hunters, Penetration Testers, and Web Developers. Instead of wasting time inspecting elements and grepping through minified JavaScript files, LPR automatically extracts and categorizes every potential injection point and hidden asset on the page. πŸš€ Key Features: πŸ•΅οΈ‍♂️ Deep Parameter Extraction: Automatically scrapes parameters from HTML forms, DOM inputs, and JavaScript variables (var, let, const). πŸ”— Advanced Asset Discovery: Digs into external .js files to find full URLs (S3 buckets, API endpoints) and hidden Routes (e.g., /api/v1/admin) that are invisible in the UI. βš”οΈ XSS & Security Scanner: proactively hunts for Dangerous Sinks (innerHTML, eval), React/Vue bypass patterns, and javascript: URIs to speed up your XSS discovery. πŸ†” IDOR Hunting: Instantly lists all ID-related patterns (e.g., user_id, order_uuid, account_id) found in the source code with line numbers. πŸ”€ Redirect Analysis: Detects potential Open Redirect vulnerabilities by scanning for window.location, meta refresh, and navigation sinks. πŸ’Ύ Accumulative Scanning: Data is saved as you browse. The extension prevents accidental tab closing to ensure you never lose your reconnaissance data during a session. Why LPR? Whether you are looking for hidden API endpoints, testing for IDORs, or hunting for DOM-based XSS, LPR gives you a bird's-eye view of the target's attack surface in seconds. Happy Hunting!

Details

  • Version
    0.6
  • Updated
    December 12, 2025
  • Offered by
    AriZionX
  • Size
    14.52KiB
  • Languages
    English
  • Developer
    Ari ZionX
    Saray Cumhuriyet, Mimar Sinan Cd No:32 Pursaklar, Ankara 06146 TR
    Email
    arizionx@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

LPR - Ultimate Recon & Bug Hunting Tool has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy .

LPR - Ultimate Recon & Bug Hunting Tool handles the following:

Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

SecuriScanX

5.0

Harden your input points - detect SQLi, XSS & CMDi within seconds.

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Subdomain Finder - Find Hidden Subdomains

5.0

The best Subdomain Finder tool for bug bounty hunters and security researchers. Find hidden subdomains quickly and easily.

DOM XSS Highlighter — Pro

0.0

Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.

GitLab MR Vulnerability Widget

5.0

Adds a widget to GitLab merge request page showing vulnerabilities detected by Container Scanning.

JS Recon Buddy

5.0

Analyze page scripts for bug bounty reconnaissance.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

Wayback Recon Pro

0.0

Reconnaissance toolkit for Wayback Machine archives. Extract URLs, subdomains, parameters, and sensitive files.

CyberPad

5.0

CyberPad: Your Ultimate Security, Development & Pen-testing Notepad

NavSec Vulnerability Scanner

5.0

Comprehensive security scanner with advanced XSS detection, API security analysis, and authentication testing

Pathprobe

5.0

Asychronous multi-domain directory scanner

SecuriScanX

5.0

Harden your input points - detect SQLi, XSS & CMDi within seconds.

CyberInject

0.0

Professional security testing toolkit for ethical hackers and penetration testers

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Subdomain Finder - Find Hidden Subdomains

5.0

The best Subdomain Finder tool for bug bounty hunters and security researchers. Find hidden subdomains quickly and easily.

DOM XSS Highlighter — Pro

0.0

Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.

GitLab MR Vulnerability Widget

5.0

Adds a widget to GitLab merge request page showing vulnerabilities detected by Container Scanning.

JS Recon Buddy

5.0

Analyze page scripts for bug bounty reconnaissance.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

Google apps
Create a Mobile Website
View Site in Mobile | Classic
Share by: