BugScanner
$20
$20
https://schema.org/InStock
usd
derek johnston
This tool performs a deep security reconnaissance scan on any website, identifying critical issues and leaks that attackers look for — including exposed secrets in JavaScript files, subdomain misconfigurations, takeover risks, CSP issues, and more.
✅ Features:
-
Full Recon Scan:
- DNS resolution & CNAME lookup
- Subdomain enumeration
- Zone transfer tests
- WAF detection
- Tech stack fingerprinting
-
JavaScript Secret Scanning:
- Detects hardcoded API keys, tokens, credentials
- Finds Stripe, AWS, Firebase, and more
- Extracts all linked JS files from the site
-
Security Weakness Detection:
- CSP & X-Frame-Options header checks
- Exposed file finder (
.env
,.git/config
, etc.) - Favicon hashing (useful for asset tracking)
- HTTP request smuggling test
-
Smart Output:
- Clean
.json
report with all findings - Easy-to-read
.txt
summary for clients or triage
- Clean
A tool to scan websites for bugs and misconfigurations
Scan for bugs
Make sure your websites doesn't have bugs
Ensure security
Make sure your website is secure
Size
5.21 KB
Add to wishlist