HiddenThings — OSINT Scanner 제작자: camael
Detects robots.txt, sitemap.xml, security.txt, and other standard or sensitive files on the visited site.
사용자 15명사용자 15명
확장 메타 데이터
스크린샷
정보
HiddenThings checks whether the site you're browsing exposes files it shouldn't — or standard files worth knowing about.
Automatic scan: on every page load, it checks for robots.txt, sitemap.xml, security.txt, and about 50 other standard/.well-known/ files. It also reads robots.txt itself and tests any extra paths listed in its Disallow/Allow/Sitemap entries.
Advanced recon (opt-in, manual): on request, it tests roughly 220 paths commonly checked in bug bounty recon — .git/, .env files, SSH keys, TLS certificates, cloud credentials, shell history files, CMS config files, debug endpoints, log files.
Custom wordlist (opt-in): paste your own list of paths to test against the current site.
Customization: Easily change the theme color and toggle between light and dark modes.
Source map discovery (opt-in): scans <script> tags on the page and checks for matching .js.map files, which sometimes leak unminified source code.
To cut down on false positives, every scan is checked against a request to a path that's guaranteed not to exist. If a site returns 200 OK for that too (common with single-page apps and custom error pages), matching results are filtered out instead of reported as found.
Each result links directly to the file and has a one-click download button.
All requests are made from the extension's own background/popup context using fetch(). Nothing is sent anywhere except to the site you're already on.
Meant for security research, bug bounty testing, and OSINT on sites you own or are authorized to test.
Automatic scan: on every page load, it checks for robots.txt, sitemap.xml, security.txt, and about 50 other standard/.well-known/ files. It also reads robots.txt itself and tests any extra paths listed in its Disallow/Allow/Sitemap entries.
Advanced recon (opt-in, manual): on request, it tests roughly 220 paths commonly checked in bug bounty recon — .git/, .env files, SSH keys, TLS certificates, cloud credentials, shell history files, CMS config files, debug endpoints, log files.
Custom wordlist (opt-in): paste your own list of paths to test against the current site.
Customization: Easily change the theme color and toggle between light and dark modes.
Source map discovery (opt-in): scans <script> tags on the page and checks for matching .js.map files, which sometimes leak unminified source code.
To cut down on false positives, every scan is checked against a request to a path that's guaranteed not to exist. If a site returns 200 OK for that too (common with single-page apps and custom error pages), matching results are filtered out instead of reported as found.
Each result links directly to the file and has a one-click download button.
All requests are made from the extension's own background/popup context using fetch(). Nothing is sent anywhere except to the site you're already on.
Meant for security research, bug bounty testing, and OSINT on sites you own or are authorized to test.
리뷰어 0명이 0점으로 평가함
권한 및 데이터
필수 권한:
- 파일을 다운로드하고 브라우저의 다운로드 기록을 읽고 수정
선택적 권한:
- 모든 웹사이트에서 사용자의 데이터에 접근
데이터 수집:
- 개발자는 이 확장 기능이 데이터 수집을 요구하지 않는다고 밝히고 있습니다.
추가 정보
- 부가 기능 링크
- 버전
- 0.1.0
- 크기
- 198.13 KB
- 최근 업데이트
- 3달 전 (2026년 7월 4일)
- 관련 카테고리
- 버전 목록
- 모음집에 추가