AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified
-
Updated
Sep 22, 2026 - Python
AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Find subdomains and urls in Javascript files
JavaScript Intelligence Engine - SPA bundle'larindan secret/endpoint/source-map cikartan tek dosya ofansif recon araci. 63 secret regex'i, Source Map V3 dekoderi, webpack chunk parser, multi-format cikti. Bug bounty + self-audit.
ScriptSentry is an advanced JavaScript security scanner designed to detect exposed secrets, vulnerabilities, and sensitive data in JavaScript files. It automatically crawls websites to discover JS files and scans them
A new package that analyzes user-provided JavaScript code snippets to determine if they can run concurrently without conflicts or race conditions. It takes the code as text input and returns a structu
AstraJS is a fast and powerful CLI-based JavaScript security analyzer that scans websites for hidden endpoints, exposed credentials, and sensitive data. It helps security researchers identify potential vulnerabilities through automated extraction, network intelligence, and detailed JSON reporting.
🔍 AI-Powered JavaScript Vulnerability Scanner & Security Automation Tool | Detect XSS, code injection, secrets & more using Google Gemini AI | Multi-purpose security engine with customizable YAML templates for penetration testing & red team operations
Next.js JS bundle API endpoint discovery tool — no wordlists, real browser interception
CVE-2026-22686-RemoteCodeExecution-RCE-PoC
JS Bundle Credential Hunter — finds hardcoded admin credentials in AI-generated websites (Next.js, Vite, React). Security research tool by @ethicalcodnoz
JavaScript/TypeScript SAST for eval, innerHTML, prototype pollution, and secrets — offline JS code security scanner.
Browser Security Monitoring (BSM): A browser-resident framework for real-time detection of JavaScript API abuse and prompt injection attacks.
To associate your repository with the javascript-security topic, visit your repo's landing page and select "manage topics."