HiddenThings — OSINT Scanner 作成者: camael
Detects robots.txt, sitemap.xml, security.txt, and other standard or sensitive files on the visited site.
11 人のユーザー11 人のユーザー
拡張機能メタデータ
スクリーンショット
この拡張機能について
HiddenThings checks whether the site you're browsing exposes files it shouldn't — or standard files worth knowing about.
Automatic scan: on every page load, it checks for robots.txt, sitemap.xml, security.txt, and about 50 other standard/.well-known/ files. It also reads robots.txt itself and tests any extra paths listed in its Disallow/Allow/Sitemap entries.
Advanced recon (opt-in, manual): on request, it tests roughly 220 paths commonly checked in bug bounty recon — .git/, .env files, SSH keys, TLS certificates, cloud credentials, shell history files, CMS config files, debug endpoints, log files.
Custom wordlist (opt-in): paste your own list of paths to test against the current site.
Customization: Easily change the theme color and toggle between light and dark modes.
Source map discovery (opt-in): scans <script> tags on the page and checks for matching .js.map files, which sometimes leak unminified source code.
To cut down on false positives, every scan is checked against a request to a path that's guaranteed not to exist. If a site returns 200 OK for that too (common with single-page apps and custom error pages), matching results are filtered out instead of reported as found.
Each result links directly to the file and has a one-click download button.
All requests are made from the extension's own background/popup context using fetch(). Nothing is sent anywhere except to the site you're already on.
Meant for security research, bug bounty testing, and OSINT on sites you own or are authorized to test.
Automatic scan: on every page load, it checks for robots.txt, sitemap.xml, security.txt, and about 50 other standard/.well-known/ files. It also reads robots.txt itself and tests any extra paths listed in its Disallow/Allow/Sitemap entries.
Advanced recon (opt-in, manual): on request, it tests roughly 220 paths commonly checked in bug bounty recon — .git/, .env files, SSH keys, TLS certificates, cloud credentials, shell history files, CMS config files, debug endpoints, log files.
Custom wordlist (opt-in): paste your own list of paths to test against the current site.
Customization: Easily change the theme color and toggle between light and dark modes.
Source map discovery (opt-in): scans <script> tags on the page and checks for matching .js.map files, which sometimes leak unminified source code.
To cut down on false positives, every scan is checked against a request to a path that's guaranteed not to exist. If a site returns 200 OK for that too (common with single-page apps and custom error pages), matching results are filtered out instead of reported as found.
Each result links directly to the file and has a one-click download button.
All requests are made from the extension's own background/popup context using fetch(). Nothing is sent anywhere except to the site you're already on.
Meant for security research, bug bounty testing, and OSINT on sites you own or are authorized to test.
0 人のレビュー担当者が 0 と評価しました
権限とデータ
必要な権限:
- ファイルのダウンロードおよびブラウザーのダウンロード履歴の読み取りと変更
任意の許可設定:
- すべてのウェブサイトの保存されたデータへのアクセス
データ収集:
- 開発者によると、この拡張機能はデータ収集を必要としません。
詳しい情報
- バージョン
- 0.1.0
- サイズ
- 198.13 KB
- 最終更新日
- 2ヶ月前 (2026年7月4日)
- 関連カテゴリー
- バージョン履歴
- コレクションへ追加