Browser Extension Threat Scanner
Seed a Chrome MV3 zip into ThreatXtension, then correlate permission and threat findings you can retest.
Aug 21, 2026
loading
14 workflows that turn a reachable surface into confirmed findings: reflected XSS, open redirects, OpenAPI IDOR/BOLA, WordPress issues, SSRF, takeover checks, and unauthenticated database exposure. Use them when you already have hosts or specs and need a repeatable check.
Between them they run httpx, nuclei, gau, qsreplace and rustscan.
14 items
Seed a Chrome MV3 zip into ThreatXtension, then correlate permission and threat findings you can retest.
Aug 21, 2026
Compare QuicDraw baseline GET vs concurrent HTTP/3 race traffic, then correlate race evidence you can retest.
Aug 21, 2026
Check a list of WordPress hosts for the wp2shell pre-auth RCE chain, CVE-2026-63030, by confirming the batch route-confusion SQLi on each one.
Aug 21, 2026
Probe embedded web chat agents for injection, prompt leak, jailbreak, and role confusion with WebAgentAudit.
Aug 21, 2026
Inventory HoneyMCP ghost tools and MCParasite channels, then correlate MCP trust-boundary findings you can retest.
Aug 21, 2026
Read a target's OpenAPI spec, enumerate every GET that takes an object id, and probe each with altered ids and stripped auth.
Aug 21, 2026
Decide allow, alert, or block on coding-agent file, shell, and network actions with AgentsLeak rules and a GolemHalt Cedar/YARA corpus.
Aug 21, 2026
Fingerprint a WordPress site's core, plugins and themes while scanning for known CVEs next to the component and version they hit.
Aug 3, 2026
Mine a domain's archived URLs for redirect parameters, then confirm which ones send a browser to an attacker-controlled host.
Aug 3, 2026
Collect a domain's archived URLs, keep parameters that reflect input, and fuzz each one for reflected and DOM cross-site scripting.
Aug 3, 2026
Crawl a target and mine its archived URLs, then test every parameter that takes a URL for server-side request forgery using out-of-band detection.
Aug 3, 2026
Turn an ASN into its live hosts, then scan the raw ports and the web surface for CVEs, misconfigurations, and exposures. Findings land in one report.
Jul 31, 2026
Find dangling CNAMEs an attacker could claim on your subdomains, with the service behind each record named so you know who to ask.
Jul 31, 2026
Port-scan a range for eight database engines and check every open service for unauthenticated access, from MongoDB and Redis to PostgreSQL.
Jul 31, 2026