Item logo image for Secret Scanner

Secret Scanner

5.0 (

1 rating

)
Item media 1 (screenshot) for Secret Scanner

Overview

Scan web pages for API keys or passwords

Scan JavaScript files loaded by websites for embedded secrets like private keys or passwords. Pages are automatically scanned in the background, and the number of found secrets is shown in the extension icon in the toolbar. Click the extension icon to see details. Limitations - Used bandwidth may increase. Consider only enabling the extension when needed on metered mobile connections. - Detected secrets may be false positives - May not catch dynamically constructed or obfuscated secrets - Does not scan scripts only loaded by other scripts. This extension is open source software licensed under the MIT license.

Details

  • Version
    0.6.0
  • Updated
    April 25, 2026
  • Offered by
    Christian Pulvermacher
  • Size
    22.25KiB
  • Languages
    English
  • Developer
    Email
    pulvermacher.christian@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Secret Scanner has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy .

Secret Scanner handles the following:

Authentication information
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

DotDrop - Sensitive File Detector

0.0

Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

SupaExplorer - Supabase & API Key Scanner

5.0

Audit Supabase RLS policies and detect exposed API keys (AWS, Stripe, OpenAI, GitHub, Google & 10+ more) in web applications.

Vulners Web Scanner

4.1

Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!

Hack-Tools

4.6

The all in one Red team extension for web pentester

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

SQL Injection Checker

5.0

Professional security testing tool for detecting SQL injection vulnerabilities

Sensitive Info Scanner

0.0

Scans webpages for potentially sensitive information like email addresses, internal IPs, or certain keywords.

SecuriScanX

5.0

Harden your input points - detect SQLi, XSS & CMDi within seconds.

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

JS Recon Buddy

5.0

Analyze page scripts for bug bounty reconnaissance.

XSSassin - Web Security Payload Injector

5.0

Security testing: inject payloads into input fields. XSS, SQLi, optional Smart-Injection (heuristic category) and more.

DotDrop - Sensitive File Detector

0.0

Detects exposed sensitive files (.git, .env, SSH keys, AWS credentials). Essential security tool for researchers & developers.

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

SupaExplorer - Supabase & API Key Scanner

5.0

Audit Supabase RLS policies and detect exposed API keys (AWS, Stripe, OpenAI, GitHub, Google & 10+ more) in web applications.

Vulners Web Scanner

4.1

Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!

Hack-Tools

4.6

The all in one Red team extension for web pentester

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

SQL Injection Checker

5.0

Professional security testing tool for detecting SQL injection vulnerabilities

Sensitive Info Scanner

0.0

Scans webpages for potentially sensitive information like email addresses, internal IPs, or certain keywords.

Google apps
Design a Mobile Site
View Site in Mobile | Classic
Share by: