
Rocket.Chat
The Secure CommsOS™ for mission-critical operations

The Secure CommsOS™ for mission-critical operations

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

CVE-2026-39154, Stored XSS in CometChat JS SDK

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

CVE-2025-55182 and CVE-2025-66478

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…