nowfound

Dev tools · alternatives · 2026

24 alternatives to JSProbeX

Pentesting tool to extract secrets & URLs from JS files

Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. JSProbeX launched in 2024; newer entries below may have overtaken it.

  1. 1

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com · its alternatives →

  2. 2SS

    Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

    2022 · socket.dev · its alternatives →

  3. 3
    JA3.pro▲93

    Bypass anti-bot systems by impersonating TLS fingerprint

    2023 · its alternatives →

  4. 4
    hat.sh▲212

    Free, fast, secure and serverless file encryption

    2019 · its alternatives →

  5. 5BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com · its alternatives →

  6. 6

    A powerful automated security testing tool

    2024 · its alternatives →

  7. 7WT
  8. 8ST
  9. 9

    The Fastest Way to Test API Security Inside Chrome DevTools

    Jul 2026 · webslurp.github.io · its alternatives →

  10. 10KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com · its alternatives →

  11. 11SO
  12. 12IB
  13. 13AM

    I made an open source, MIT license Typescript library based on some of the latest research that generates prompt injection attacks. It is a super minimal/lightweight and designed to be super easy to use. Keen to hear your thoughts and please be responsible and only pen test systems where you have permission to pen test!

    2025 · prompt-injector.blueprintlab.io · its alternatives →

  14. 14IB

    BoringSSL and nghttp2. Matches JA3N, JA4, and JA4_R fingerprints. Supports HTTP/2, async/await, and works with Cloudflare-protected sites. Not trying to compete with curl_cffi - just a learning project that turned into something functional.

    Nov 2025 · github.com · its alternatives →

  15. 15FA

    I made FingerprinterJS, a small library with no dependencies that creates browser fingerprints from signals like canvas, WebGL, audio, fonts, userAgent, and screen info. It’s written in TypeScript, lets you enable/disable collectors, add custom data, and includes a simple suspicious-activity score. Would love feedback.

    Sep 2025 · github.com · its alternatives →

  16. 16AS

    Free and instant penetration testing for rest APIs. Please try and let me know what do you think? https://www.apisec.ai/free-api-pen-test

    2022 · its alternatives →

  17. 17

    Security Tool

    Mar 2026 · jsshield.qzz.io · its alternatives →

  18. 18

    Secret scanning for shipped-too-fast websites

    Jan 2026 · supaleak.com · its alternatives →

  19. 19

    Free, privacy-first web tools. No uploads, no logins.

    Dec 2025 · jwtoolbox.com · its alternatives →

  20. 20OJ
  21. 21

    High level protection

    Oct 2025 · obfuscatorjs-seven.online · its alternatives →

  22. 22IH

    A simple Go-based HTTP proxy designed for detailed inspection of requests and responses. It logs traffic to the console with colorization, automatic decompression, and formatting for common content types, while remaining transparent to the client application. Ideal for debugging API interactions, understanding middleware behavior, or simply getting a clear view of HTTP traffic flow with jq-like pretty-printing & colorization of request/response. Automatically redacts parts of Authorization header to avoid token leakage.

    2025 · github.com · its alternatives →

  23. 23

    Swiss-army dev toolkit: JSON, IP, URL & more — free forever

    2025 · whatthe.tools · its alternatives →

  24. 24JI

Also compare

Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →