Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dj — Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source maps for recon. | Kitploit
Tools/GitHubGitHub/ejfkdev/dj
OSINT (Open Source Intelligence)ReconnaissanceStatic AnalysisScripting & AutomationInformation GatheringWeb SecurityUtilities & FrameworksCrawlerAnti-BotFingerprint Spoofing
GitHubejfkdev/dj
524441 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

dj

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source maps for recon.

View Repository

dj - Dynamic JS File Extractor

中文 | English

Go Version License Release Build Stars Forks Issues Downloads

dj intelligently detects dynamically loaded JavaScript files by statically analyzing website HTML and JS code, including webpack chunks, import() lazy loading, and more.

Features

  • Deep analysis of website HTML and JS to extract dynamically loaded JavaScript files
  • Smart detection of dynamic loading patterns: import(), require(), webpack chunks, vite preload, etc.
  • Support for multiple frontend framework chunk mappings: Next.js, Nuxt.js, Vite, SvelteKit, Webpack, and more
  • Automatic Source Map discovery and original source code restoration (from sourcesContent, with mappings VLQ fallback)
  • Cache reuse: second run on the same site restores results from local cache with zero network requests
  • TLS fingerprint impersonation with fixed Chrome profile by default — TLS fingerprint, User-Agent and Sec-CH-* headers all come from one consistent browser profile. Measured on WAF/CDN sites: rotating fingerprints gets JA3-blocked (a site answering 476 JS to fixed Chrome answered 11 to rotation), so --random-tls is opt-in
  • Deterministic output: JS URLs are sorted, so the same site yields the same URL set and order on every run (stable diffs and regressions)
  • HTTP/2 and HTTP/1.1 protocol auto-negotiation
  • SOCKS5/HTTP/HTTPS proxy support with authentication
  • Environment variable proxy configuration (HTTPS_PROXY, ALL_PROXY, NO_PROXY, etc.)
  • Custom User-Agent and browser-like request headers
  • Multiple output formats: text, JSON, markdown
  • Three interfaces, one definition (via xyz-go): CLI (dj scan / legacy dj <url>), HTTP REST API (dj serve with /openapi.json), and MCP tool server (dj mcp stdio|sse|http)

Supported Frameworks & Loading Models

dj's extractor is verified against real build output across 74 frameworks / loading models and 572 versions.

CategoryFrameworks
Bundlers (15)webpack, webpack4, vite, vite-plus, rollup, esbuild, parcel, rsbuild, rspack, farm, mako, rolldown, systemjs, snowpack, turbopack
Microfrontend frameworks (17)qiankun, single-spa, micro-app, wujie, garfish, icestark, piral, luigi, emp, hel-micro, native-federation, module-federation, mf-runtime, mf-vite, mf-rsbuild, webpack-mf, vite-plugin-federation
Meta frameworks / SSR (25)nuxt, sveltekit, angular, astro, qwik, solidstart, tanstack-start, marko, react-router, remix2, redwood, analog, vike, hono, one, fresh, stencil, storybook, gatsby, cra, umi, icejs, vue-cli, modernjs, bun
Rust / WASM frontends (3)leptos, lustre, trunk
Admin templates (12)ant-design-pro, amis, ng-alain, jeecg, d2admin, pig-ui, tdesign-starter, vue-element-admin, vue-pure-admin, vue-vben-admin, ruoyi-vue2, ruoyi-vue3
Spec / polyfills (1)es-module-shims

Version details (click to expand)

Bundlers (15 — expand for verified versions)
FrameworkNotesVerified versions
webpackwebpack 5 runtime chunk mapsv5.0.0 ~ v5.110.3(19 个版本)
webpack4webpack 4 JSONP runtimev4.33.0 ~ v4.47.0(15 个版本)
vitedynamic import / modulepreload / prefetch / .vite manifest probev3.0.9 ~ v8.3.0(14 个版本)
vite-plusVite+ (VoidZero) vp build = Vite 8/Rolldown output + .vite manifestv0.3.1(1 个版本)
rollupmulti-entry + dynamic importv2.0.6 ~ v4.63.2(19 个版本)
esbuildesbuild outputv0.14.54 ~ v0.28.2(15 个版本)
parcelparcel outputv2.0.1 ~ v2.16.4(4 个版本)
rsbuildrsbuild / rspack ecosystem (2.x is rspack-based)v1.0.19 ~ v2.2.5(10 个版本)
rspackruntime hash maps (2.x rspackChunk runtime)v1.0.14 ~ v2.2.3(11 个版本)
farmRust bundlerv0.1.1 ~ v1.0.5(5 个版本)
makoByteDance makov0.4.17 ~ v0.11.15(8 个版本)
rolldownrolldownv0.9.2 ~ v1.2.8(11 个版本)
systemjsSystemJS outputv0.21.6 ~ v6.15.1(17 个版本)
snowpackunbundled ESM outputv2.18.5 ~ v3.8.8(10 个版本)
turbopackNext.js turbopackv15.3.9 ~ v16.3.5(8 个版本)
Microfrontend frameworks (17 — expand for verified versions)
FrameworkNotesVerified versions
qiankunqiankun 2.x (incl. vite-plugin-qiankun)v2.1.1 ~ v2.10.16(10 个版本)
single-sparoot configv4.4.4 ~ v6.0.3(12 个版本)
micro-appmicro-appv0.1.0 ~ v0.8.11(8 个版本)
wujiewujiev1.0.29 ~ v2.1.0(3 个版本)
garfishgarfishv1.0.26 ~ v1.19.12(10 个版本)
icestarkicestarkv1.0.0 ~ v2.8.4(11 个版本)
piralpiralv1.1.0 ~ v1.12.2(12 个版本)
luigiluigiv0.0.9 ~ v1.7.11(10 个版本)
emp@efox/empv1.0.34 ~ v1.10.2(11 个版本)
hel-microhel-microv3.5.16 ~ v4.15.3(10 个版本)
native-federationnative federationv0.9.1 ~ v4.4.1(11 个版本)
module-federation@module-federation/enhancedv0.0.17 ~ v2.8.2(11 个版本)
mf-runtimeMF runtime onlyv2.1.0 ~ v2.8.2(8 个版本)
mf-viteMF vite integrationv1.13.7 ~ v1.20.7(8 个版本)
mf-rsbuildMF rsbuild pluginv2.1.0 ~ v2.8.2(8 个版本)
webpack-mfwebpack built-in MFv5.98.0 ~ v5.108.4(10 个版本)
vite-plugin-federationOrigin.js federationv0.0.3 ~ v1.4.1(6 个版本)
Meta frameworks / SSR (25 — expand for verified versions)
Download Tool