↩
HTTP Repeater
Capture, edit, and replay any request in seconds. Grab any HTTP/HTTPS request from the page, modify the method, URL, headers, or body, and fire it again. Work across multiple tabs with full history.
- Edit & replay any captured request
- Multiple tabs with history
- Pretty JSON + raw + headers + timing
- Copy as cURL in one click
⚡
Intruder
Fuzz parameters at scale without leaving your browser. Mark injection points with §payload§ markers, load a wordlist or number range, and fire up to 20 concurrent requests. Spot anomalies instantly in the results table.
- §marker§ payload positions
- Simple list or number range payloads
- Concurrent requests (up to 20)
- Results table with diff + response viewer
⇄
Decoder
Decode, encode, and inspect tokens instantly. Convert between Base64, URL, Hex, and HTML entities in one click. Inspect JWT payloads without leaving DevTools.
- Base64 encode / decode
- URL encode / decode
- Hex encode / decode
- HTML entities + JWT inspection
🔍
Client-Side Scanner
Audit client-side security in one click. Automated passive and active checks run as you browse — missing headers, insecure storage, DOM XSS patterns, CORS misconfigurations, and more. Findings appear instantly, no manual steps required.
- Storage & cookie security checks
- Missing security headers (CSP, HSTS)
- DOM XSS + postMessage patterns
- JWT alg=none + CORS reflection
- IDOR & SQLi detection (active mode)
🧠
Tech Detector
Know what's running and what's vulnerable. Passively fingerprint frameworks, libraries, and versions from network traffic. Map every detection to known CVEs using a local database — no external API calls.
- Framework & library detection
- Version extraction from headers/bodies
- Local CVE database mapping
- Export recon bundle as JSON/CSV
🔑
Secret Scanner
Find leaked credentials before attackers do. Scans every response in real time for API keys, tokens, and credentials across 50+ patterns. Everything runs locally in your browser — nothing leaves your machine.
- AWS, GCP, Azure, Stripe, GitHub keys
- JWT, OAuth tokens, database URIs
- Scans runtime/build JS chunks automatically
- Local validation — no secrets leave your browser
- Export findings as JSON or CSV
🌐
WordPress Audit
Full WordPress recon without external tools. Enumerate plugins, themes, and core version from captured traffic. Map every detection to known CVEs and scan custom endpoints with your own wordlists.
- Plugin & theme enumeration
- WordPress core version detection
- CVE mapping for detected versions
- Endpoint scanner with custom wordlists
💡
AI Assist
Get test suggestions tailored to each endpoint. Select any request and get instant analysis — endpoint purpose, risk classification, and specific security tests to run. 100% local pattern matching, no data leaves your browser.
- Endpoint purpose detection
- Tailored security test suggestions
- Risk classification per endpoint
- 100% local — no API calls