
JSProbeX
Pentesting tool to extract secrets & URLs from JS files
What it does
Penetration testing tool that extracts sensitive information such as API keys, secret tokens, and URLs from JavaScript files. It helps penetration testers and bug bounty hunters efficiently identify exposed credentials and security risks in JS files and URLs.
Does a similar job
all alternatives →
Osint tool that finds exposed files on domainsJul 2026 · search.cerast-intelligence.com · ▲58hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…
- SSSocket – Secure your JavaScript supply chain2022 · socket.dev · ▲133
Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

- WTWeb tool which spits out hardcoded secret API tokens in apps2016 · android.fallible.co · ▲24
WebSlurpJul 2026 · webslurp.github.io · ▲9The Fastest Way to Test API Security Inside Chrome DevTools
- KDKeyLeak Detector – Scan websites for exposed API keys and secretsNov 2025 · github.com · ▲30
I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…
More dev tools this month
the category →



OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 4d ago · opentrailpaper.com

Lettertrace▲375Track your AI visibility for free (using your own API keys!)
Dev tools · 28d ago · lettertrace.com
Source: Product Hunt launch ↗