Free Chrome Extension · No Proxy Required

Security Testing
Inside DevTools

HackTools++ brings Burp Suite-style security testing directly into Chrome DevTools. Capture, edit and replay HTTP requests, fuzz endpoints, scan for secrets and CVEs — all without installing a proxy or certificate.

8 Built-in Tools
0 Setup Required
100% Free & Open

Everything You Need in One Panel

8 integrated security tools that work together without leaving Chrome DevTools.

HTTP Repeater

Capture any HTTP/HTTPS request, edit method, URL, headers and body, then replay it instantly. Multi-tab support with full request history.

  • Edit & replay any captured request
  • Multiple tabs with history
  • Pretty JSON + raw + headers + timing
  • Copy as cURL in one click

Intruder

Fuzz any parameter in the URL, headers, or body. Mark injection points with §payload§ markers and run automated attacks with custom payloads.

  • §marker§ payload positions
  • Simple list or number range payloads
  • Concurrent requests (up to 20)
  • Results table with diff + response viewer

Decoder

Encode and decode data in multiple formats instantly. Inspect JWT payloads without leaving DevTools.

  • Base64 encode / decode
  • URL encode / decode
  • Hex encode / decode
  • HTML entities + JWT inspection

Client-Side Scanner

Automated passive + active security checks against the loaded page. No manual steps — findings appear automatically as you browse.

  • Storage & cookie security checks
  • Missing security headers (CSP, HSTS)
  • DOM XSS + postMessage patterns
  • JWT alg=none + CORS reflection
  • IDOR & SQLi detection (active mode)

Tech Detector

Passively fingerprint the technology stack from captured network traffic. Map detected versions to known CVEs locally — no API calls needed.

  • Framework & library detection
  • Version extraction from headers/bodies
  • Local CVE database mapping
  • Export recon bundle as JSON/CSV

Secret Scanner

Real-time local scanning of runtime JavaScript and API responses for leaked credentials. 50+ signature rules covering every major provider.

  • AWS, GCP, Azure, Stripe, GitHub keys
  • JWT, OAuth tokens, database URIs
  • Scans runtime/build JS chunks automatically
  • Local validation — no secrets leave your browser
  • Export findings as JSON or CSV

WordPress Audit

Specialized passive audit for WordPress sites. Detect plugins, themes, versions and known CVEs from captured traffic.

  • Plugin & theme enumeration
  • WordPress core version detection
  • CVE mapping for detected versions
  • Endpoint scanner with custom wordlists

AI Assist

Instant endpoint analysis and security test suggestions based on the selected request. Pattern-matched locally, no data leaves your browser.

  • Endpoint purpose detection
  • Tailored security test suggestions
  • Risk classification per endpoint
  • 100% local — no API calls

Watch HackTools++ in Action

Real demos showing how to use each tool for security testing.

Demo

HTTP Repeater & Request Capture

How to capture, edit and replay HTTP requests inside Chrome DevTools.

Demo

Intruder & Fuzzing

Setting up payload positions and running automated fuzzing attacks with Intruder.

Demo

Secret Scanner & CVE Detection

Automatically detecting leaked secrets and CVEs from runtime JavaScript assets.

Up and Running in 60 Seconds

No proxy setup, no certificates, no configuration files.

  1. Install the Extension

    Add HackTools++ from the Chrome Web Store. It's free and takes under 10 seconds.

  2. Open DevTools

    Press F12 or Cmd+Option+I on any page. Click the HackTools++ tab.

  3. Browse the Target

    Navigate or refresh. Requests are captured automatically in the left panel.

  4. Test & Exploit

    Click any request, edit it, replay it, send it to Intruder, or wait for Scanner to flag issues automatically.

What's Coming Next

Features actively planned or in development. Roadmap is updated with each release.

Coming Soon

GraphQL Inspector

Detect GraphQL endpoints, introspect schemas, and test queries for IDOR, injection, and excessive data exposure.

Coming Soon

Request Sequences

Record and replay multi-step request chains. Ideal for testing auth flows, CSRF, and session management.

Planned

Export to Burp / Postman

One-click export of captured requests and findings into Burp Suite XML or Postman collection format.

Planned

Custom Scanner Rules

Write and import your own YAML-based detection rules for the client-side scanner and secret detector.

Planned

Response Diff Viewer

Side-by-side comparison of two responses to spot subtle differences in IDOR, access control, and A/B test bypasses.

Research

API Contract Testing

Validate API responses against OpenAPI / Swagger specs. Flag undocumented endpoints and schema violations automatically.

Frequently Asked Questions

Start Testing in 60 Seconds

Free forever. No proxy. No setup. Just open DevTools and go.

Add to Chrome — Free