JSHarvest by hawtsauce
Inventory every JavaScript file a page loads — deduplicated and classified first- vs third-party — with source-map recovery, hidden-chunk discovery, risk flags and export to TXT, JSON, CSV, HAR or a wordlist.
Available on Firefox for Android™Available on Firefox for Android™
Scan the QR code to open this extension in Firefox for Android
Extension Metadata
Screenshots
About this extension
JSHarvest builds a complete, deduplicated inventory of the JavaScript running on any page you visit. Everything is processed locally in your browser — no analytics, no telemetry, no account.
What it captures
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
What it captures
- Network requests, DOM sources (script tags, preloads, module preloads, import maps, inline references) and Worker / ServiceWorker registrations — merged into one deduplicated list.
- Classification for every file: first-party vs third-party, bundler output, source maps, and the vendor behind it (Google, Meta, Stripe, Sentry and many more).
- Risk flags: third-party scripts loaded without Subresource Integrity, mixed content, and failed or 4xx responses.
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Extend developer tools to access your data in open tabs
- Access browser tabs
- Access browser activity during navigation
- Access your data for all web sites
Optional permissions:
- Access your data for all web sites
Data collection:
- The developer says this extension doesn't require data collection.
Optional data collection, according to the developer:
- Web site activity
- Web site content
More information
- Add-on Links
- Version
- 1.1.0
- Size
- 133.01 kB
- Last updated
- 3 days ago (25 Aug 2026)
- Related Categories
- Licence
- MIT Licence
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection