Item logo image for rep+

rep+

Featured
5.0 (

31 ratings

)
Item media 4 (screenshot) for rep+
Item media 5 (screenshot) for rep+
Item media 1 (screenshot) for rep+
Item media 2 (screenshot) for rep+
Item media 3 (screenshot) for rep+
Item media 4 (screenshot) for rep+
Item media 5 (screenshot) for rep+
Item media 1 (screenshot) for rep+
Item media 2 (screenshot) for rep+
Item media 1 (screenshot) for rep+
Item media 2 (screenshot) for rep+
Item media 3 (screenshot) for rep+
Item media 4 (screenshot) for rep+
Item media 5 (screenshot) for rep+

Overview

rep+ - Capture, modify, and replay HTTP requests in Chrome DevTools with AI-powered security analysis.

rep+ is a powerful Chrome DevTools extension that brings Burp Suite Repeater functionality directly into your browser. Now enhanced with AI, it helps developers, security researchers, and bug bounty hunters test and analyze HTTP requests smarter and faster—no proxy setup required. With rep+ you can: - Capture and replay HTTP requests from any tab, without proxy setup - Group, filter, block, and search requests using text or regex - Convert data inline (Base64, URL encode/decode, JWT decode, Hex/UTF‑8) - Inspect responses in multiple formats with syntax highlighting and line numbers - Passively extract hidden endpoints from JavaScript - Discover query, body, header, and path parameters with risk classification and confidence scoring - Suppress false positives by ignoring common frameworks, libraries, telemetry, and generic fields - Detect secrets in JavaScript using high‑coverage Kingfisher rules - Export endpoints, parameters, and secrets to CSV or Postman - Search deeply inside responses and JavaScript - Run built‑in automated attacks (Sniper, Battering Ram, Pitchfork, Cluster Bomb) - Use AI for request explanations and attack suggestions via API or local LLM (Ollama) - AI‑powered request analysis, modification, and attack suggestions - Per‑request isolated chat with cross‑request references - One‑click AI‑driven request edits with visual feedback - Local or API‑based LLM support with aggressive token optimization - Automatically remove duplicate requests during capture to eliminate noise and keep only unique traffic Why install it? - Works natively inside your browser - Designed for speed, clarity, and real pentesting workflows - Helps you uncover security issues and understand application behaviour faster - Ideal for bug bounty hunters, red teamers, AppSec, and curious devs

Details

  • Version
    1.3.1
  • Updated
    January 14, 2026
  • Offered by
    Bour Abdelhadi
  • Size
    525KiB
  • Languages
    English
  • Developer
    Email
    borabdelhadi@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy .

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

Gecko

5.0

Automated CSPT discovery tool

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

Shodan

4.6

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

DOMLogger++

5.0

DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

DotGit

4.8

An extension for checking if .git is exposed in visited websites

Endpoint Extractor

5.0

Extracts endpoints from the current page.

Hack-Tools

4.6

The all in one Red team extension for web pentester

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

Jsmon Chrome Extension

5.0

Fetches and scans JS urls from network history

EndPointer

5.0

An endpoint parser and extractor with many flexible features

Gecko

5.0

Automated CSPT discovery tool

S3BucketList

3.5

S3BucketList automatically scans network requests made by your browser to detect Amazon S3 bucket URLs

Shodan

4.6

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

DOMLogger++

5.0

DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

DotGit

4.8

An extension for checking if .git is exposed in visited websites

Endpoint Extractor

5.0

Extracts endpoints from the current page.

Hack-Tools

4.6

The all in one Red team extension for web pentester

Google apps
Design a Mobile Site
View Site in Mobile | Classic
Share by: