JSHarvest 제작자: hawtsauce
Inventory every JavaScript file a page loads — deduplicated and classified first- vs third-party — with source-map recovery, hidden-chunk discovery, risk flags and export to TXT, JSON, CSV, HAR or a wordlist.
Android™용 Firefox에서 사용 가능Android™용 Firefox에서 사용 가능
Android용 Firefox에서 이 확장 기능을 열려면 QR 코드를 스캔하세요
확장 메타 데이터
스크린샷
정보
JSHarvest builds a complete, deduplicated inventory of the JavaScript running on any page you visit. Everything is processed locally in your browser — no analytics, no telemetry, no account.
What it captures
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
What it captures
- Network requests, DOM sources (script tags, preloads, module preloads, import maps, inline references) and Worker / ServiceWorker registrations — merged into one deduplicated list.
- Classification for every file: first-party vs third-party, bundler output, source maps, and the vendor behind it (Google, Meta, Stripe, Sentry and many more).
- Risk flags: third-party scripts loaded without Subresource Integrity, mixed content, and failed or 4xx responses.
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
리뷰어 0명이 0점으로 평가함
권한 및 데이터
필수 권한:
- 열려있는 탭의 데이터에 접근하도록 개발자 도구 확장
- 브라우저 탭에 접근
- 탐색 중 브라우저 활동에 접근
- 모든 웹사이트에서 사용자의 데이터에 접근
선택적 권한:
- 모든 웹사이트에서 사용자의 데이터에 접근
데이터 수집:
- 개발자는 이 확장 기능이 데이터 수집을 요구하지 않는다고 밝히고 있습니다.
개발자가 밝인 선택적 데이터 수집:
- 웹사이트 활동
- 웹 사이트 콘텐츠
추가 정보
- 부가 기능 링크
- 버전
- 1.1.0
- 크기
- 133.01 KB
- 최근 업데이트
- 8일 전 (2026년 8월 25일)
- 관련 카테고리
- 라이선스
- MIT 라이선스
- 개인정보처리방침
- 이 부가 기능에 대한 개인정보처리방침 읽기
- 버전 목록
- 모음집에 추가