SecuriScan - Web Security Analyzer
SecuriScan is a powerful Chrome extension that performs comprehensive passive security analysis on any website. Built for developers, security professionals, and anyone who wants quick security insights without setting up complex tools like Burp Suite or OWASP ZAP. š šŖššš§'š¦ š”ššŖ šš” š©š.š°.š¬ ⢠š” OWASP Top 10 view ā maps every finding to the OWASP Top 10 (2021) with PASS/WARN/FAIL badges ⢠š¤ AI Explain & Fix ā one-click explanations and copy-paste code fixes for every vulnerability found ⢠š Side Panel mode ā persistent scanning panel that stays open alongside your browsing (Alt+Shift+P) ⢠š¢ Toolbar badge ā live issue count on the extension icon, colour-coded by severity ⢠š” Network security scan ā detects insecure WebSockets (ws://), WebRTC IP leakage, unsafe postMessage usage, hardcoded private IPs, and dynamic script injection ⢠ā SARIF 2.1.0 export ā export results in industry-standard SARIF format for CI/CD pipeline integration ⢠⨠Keyboard shortcuts ā Alt+Shift+S to scan, Alt+Shift+P to open the side panel ⢠š± Right-click context menu ā scan any page directly from the right-click menu ⢠ā Settings tab ā toggle auto-scan (opt-in, off by default), desktop notifications, and badge display ⢠š Score sparklines ā visual score history chart per domain in the History tab š šŖššš§'š¦ š”ššŖ šš” š©š.šÆ.š¬ ⢠š Privacy tracker detection ā flags 18 third-party trackers including Meta Pixel, TikTok, Hotjar, FullStory, and more ⢠š¾ Browser storage audit ā scans localStorage and sessionStorage for exposed tokens, keys, and PII ⢠š Scan history & score trends ā tracks your last 10 scans per domain and shows ā/ā trend on every result ⢠š JSON export ā export results as machine-readable JSON alongside the existing HTML report š šŖššš§ šš§ šš¢šš¦ When you click scan, SecuriScan analyzes the current page for security misconfigurations and vulnerabilities across 13 categories: š š¦š²š°ššæš¶šš šš²š®š±š²šæš (šš¬ š°šµš²š°šøš) ⢠Content-Security-Policy (CSP) ⢠Strict-Transport-Security (HSTS) ⢠X-Frame-Options ⢠X-Content-Type-Options ⢠Referrer-Policy ⢠Permissions-Policy ⢠Cross-Origin-Opener-Policy ⢠Cross-Origin-Resource-Policy ⢠Cross-Origin-Embedder-Policy ⢠X-XSS-Protection šŖ šš¼š¼šøš¶š² š¦š²š°ššæš¶šš ⢠HttpOnly and Secure flag validation ⢠Session token exposure detection ⢠Sensitive cookie pattern matching ⢠SameSite attribute guidance š š©šš¹š»š²šæš®šÆš¹š² šš®šš®š¦š°šæš¶š½š šš¶šÆšæš®šæš¶š²š (šÆš±+ š¹š¶šÆšæš®šæš¶š²š) š“ Critical Severity: ⢠Handlebars < 4.7.7 (arbitrary code execution) ⢠Socket.IO < 4.4.1 (CORS bypass) ⢠Minimist < 1.2.6 (prototype pollution) ⢠EJS < 3.1.7 (template injection) š High Severity: ⢠jQuery < 3.5.0 (CVE-2020-11022, CVE-2020-11023) ⢠AngularJS < 1.8.3 (CVE-2023-26116) ⢠Lodash < 4.17.21 (CVE-2021-23337, CVE-2020-28500) ⢠React < 16.14.0 (CVE-2021-23648) ⢠Vue.js < 2.6.14 (CVE-2021-3766) ⢠Marked < 4.0.10 (ReDoS and XSS) ⢠DOMPurify < 2.3.10 (XSS bypass) ⢠Express < 4.17.3 (open redirect) ⢠Webpack < 5.76.0 (cross-realm access) ⢠Underscore < 1.13.0 (code execution) ⢠Next.js < 12.3.2 (open redirect) ⢠Nuxt.js < 2.15.7 (directory traversal) ⢠Pug < 3.0.1 (code injection) š” Medium Severity: ⢠Bootstrap < 4.3.1 (CVE-2019-8331) ⢠Moment.js < 2.29.4 (CVE-2022-31129) ⢠Axios < 0.21.3 (SSRF) ⢠D3.js, Chart.js, DataTables, and more š š¦š²š»šš¶šš¶šš² šš®šš® šš š½š¼šššæš² (š®š±+ š½š®ššš²šæš»š) š API Keys & Tokens: ⢠AWS Access/Secret Keys ⢠Google API Keys & OAuth ⢠GitHub Personal Access Tokens ⢠Stripe API Keys (live & test) ⢠Slack Tokens ⢠Twilio, SendGrid, Mailgun API Keys ⢠PayPal Braintree Tokens ⢠Square OAuth Secrets ⢠Shopify Access Tokens & Shared Secrets ⢠Generic API key patterns š Credentials & Secrets: ⢠Private Keys (RSA, SSH, EC, PGP, OpenSSH) ⢠Database Connection Strings (MongoDB, MySQL, PostgreSQL) ⢠JWT Tokens ⢠Passwords in source code ⢠Firebase URLs šŖŖ PII: ⢠Credit Card Patterns ⢠Social Security Numbers ⢠Email Addresses (filtered for false positives) š š£šæš¶šš®š°š š§šæš®š°šøš²šæš Detects 18 third-party tracking scripts that collect and share your users' behavioral data: ⢠š„ Session recorders: Hotjar, FullStory, Mouseflow, Crazy Egg ⢠š¢ Ad pixels: Meta/Facebook, TikTok, Twitter/X, LinkedIn Insight ⢠š Analytics: Google Analytics, Google Tag Manager, Mixpanel, Amplitude, Heap, Clarity ⢠š¬ CRM: HubSpot, Intercom, Pardot, Segment Each tracker is rated by severity ā session recorders (high) vs. analytics-only (medium) ā so you know which ones are most invasive. š¾ ššæš¼ššš²šæ š¦šš¼šæš®š“š² ššš±š¶š Scans localStorage and sessionStorage for sensitive data that XSS could steal: ⢠Auth tokens, JWT, session IDs stored under sensitive key names ⢠API keys, AWS credentials, private keys in stored values ⢠Credit card numbers and SSNs ⢠Flags risky storage patterns and recommends HttpOnly cookies instead š” š”š²ššš¼šæšø š¦š²š°ššæš¶šš (š”ššŖ š¶š» šš.š°.š¬) Passively inspects inline scripts for risky network patterns: ⢠Insecure WebSocket connections using ws:// instead of wss:// ⢠WebRTC usage that can leak real IP addresses through VPNs ⢠postMessage() calls without event.origin validation ⢠Hardcoded private/internal IP addresses (192.168.x, 10.x, 127.0.0.1) ⢠Dynamic <script> element injection ⢠Hardcoded cross-origin fetch endpoints ā ļø šš¼šŗšŗš¼š» š©šš¹š»š²šæš®šÆš¶š¹š¶šš¶š²š ⢠Mixed content detection (HTTP resources on HTTPS pages) ⢠Forms submitting over insecure connections ⢠Missing CSRF token detection ⢠Password fields on non-HTTPS pages ⢠Credit card/SSN fields without HTTPS ⢠Inline event handlers (onclick, onload, etc.) ⢠JavaScript URLs and data: URLs ⢠eval() and dangerous DOM manipulation ⢠Exposed API keys and credentials in source š” šš±š±š¶šš¶š¼š»š®š¹ š¦š²š°ššæš¶šš ššµš²š°šøš ⢠Subresource Integrity (SRI) validation for CDN resources ⢠CORS configuration analysis ⢠Enhanced XSS detection with 10+ event handler types ⢠srcdoc attribute usage in iframes ⢠URL manipulation pattern detection āļø šš¢šŖ šš§ šŖš¢š„šš¦ All analysis runs locally in your browser. SecuriScan inspects the DOM, checks response headers via fetch, and pattern-matches against a comprehensive vulnerability database with CVE tracking. No data leaves your machine. Results are presented with a 0ā100 security score using severity-based weighting (Critical/High/Medium/Low). A trend indicator (ā/ā/ā) shows how the score changed since your last scan of that domain. The OWASP tab maps every finding to the OWASP Top 10 (2021) so you can communicate risk in a language your team understands. Click any category to see specific findings with remediation guidance and CVE references. Every vulnerability includes a š¤ Explain & Fix button with a plain-English explanation and a copy-paste code fix. Export as a formatted HTML report, machine-readable JSON, or SARIF 2.1.0 for CI/CD pipelines and client deliverables. š„ šŖšš¢ šš§'š¦ šš¢š„ ⢠šØāš» Frontend developers checking sites before deployment ⢠š Security engineers doing quick reconnaissance ⢠š DevOps teams validating production configurations ⢠šÆ Penetration testers performing initial assessments ⢠š¼ Freelancers auditing client websites ⢠š Students learning web security fundamentals ⢠š Anyone concerned about website security š§ š§šššš”šššš ššš§šššš¦ Built on Manifest V3 with minimal permissions: ⢠activeTab ā access current page when you click scan ⢠scripting ā inject analysis code into the page ⢠storage ā cache scan results and history locally ⢠tabs ā read current tab URL for history tracking ⢠sidePanel ā enable the persistent side panel (v1.4.0) ⢠contextMenus ā add right-click scan option (v1.4.0) ⢠notifications ā optional alerts for critical findings (v1.4.0, opt-in) ⨠New in v1.4.0: ⢠OWASP Top 10 (2021) compliance view ⢠AI-powered Explain & Fix for every finding ⢠Persistent side panel mode ⢠Toolbar badge with live issue count ⢠Network & API security scanning ⢠SARIF 2.1.0 export ⢠Keyboard shortcuts (Alt+Shift+S / Alt+Shift+P) ⢠Right-click context menu integration ⢠Configurable auto-scan (opt-in, off by default) ⢠Settings tab with notification and badge controls No telemetry. No external API calls. The entire codebase is open source if you want to audit it or contribute. š« ššš šš§šš§šš¢š”š¦ This is a passive scanner, not a penetration testing tool. It cannot: ⢠Test for server-side vulnerabilities (SQLi, SSRF, RCE, etc.) ⢠Intercept or modify HTTP traffic ⢠Perform authenticated scanning ⢠Detect all possible security issues ⢠Replace a proper security audit by professionals Think of it as a comprehensive health check and reconnaissance tool, not a replacement for professional security testing. šµļø š£š„šš©ššš¬ Zero data collection. No analytics. No tracking. No external servers. Everything stays on your device. Built by developers, for developers. No fluff, just useful security insights with real CVE tracking, OWASP mapping, and actionable remediation guidance.