
BurpMetaFinder
Burp Suite extension for extracting metadata from files

Burp Suite extension for extracting metadata from files

A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues

A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!

Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Modular Burp Suite extension for fine-grained highlighting and extraction of sensitive data from HTTP and WebSocket traffic, enabling efficient…

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

A chromium extension exploitation toolkit

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2