The TruffleHog chrome extension looks for API keys and credentials on websites visited, and alerts you if there are any present. This is useful for doing pentests and code reviews, because it helps identify keys that would otherwise either be missed or have to be searched for manually
You can Follow the below Step By Step procedure to install the Trufflehog Chrome Extension to your Chrome Web browser.
It is the Trufflehog Chrome extension download link you can download and install Chrome Browser.
The all in one Red team extension for web pentester
The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.
Scanning website for vulnerable js libraries
This extension tells if visited sites have vulnerability disclosure programs
An extension for checking if .git is exposed in visited websites
Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!
OWASP Penetration Testing Kit
Search websites for git repos, exposed config files, and more as you browse.
在网页的源代码或js中找到一些有趣的东西
Web Development tool