Firefox Browser Add-ons
Log in
Preview of SQLiBar

SQLiBar by bLackn3x

SQLiBar – Pentesting & SQLi Toolkit A Developer Tools extension for security testing, real-time SQL injection pattern detection, request manipulation, parameter discovery, and payload encoding.

5 (1 review)5 (1 review)
Download Firefox and get the extension
Download file

Extension Metadata

Screenshots
About this extension
SQLiBar – Pentesting & SQLi Toolkit
A Developer Tools extension for security testing, real-time SQL injection pattern detection, request manipulation, parameter discovery, advanced payload encoding, and multi-language UI support.
Description
SQLiBar is an advanced web penetration testing tool built into Firefox Developer Tools. Designed for security researchers, penetration testers, and web developers, it streamlines parameter analysis, HTTP request building, SQL injection vulnerability testing, and response inspection directly from your browser.
SQL Injection Detection & Pattern Analysis

Automated response analysis against 100+ database-specific error patterns (MySQL, MariaDB, PostgreSQL, MSSQL, Oracle, SQLite, DB2, Sybase, Access, H2, Firebird, and common ORMs such as PDO, SQLAlchemy, Django, Laravel, Hibernate, Entity Framework, Prisma, and more)
Baseline comparison: set response length and timing baselines to catch subtle anomalies (Boolean-based, Union-based, Error-based, and Time-based indicators)
Reflection detection: highlights payload fragments that appear in the response
Diff view: line-based comparison against the stored baseline body
Visual severity indicators (high / medium / low) with code snippet context for identified error signatures

Smart Page Parameter Scanner

Scans the current page DOM to discover form fields, hidden inputs, URL query parameters, link parameters, data-* attributes, and cookies
Instantly push discovered parameters to the URL query, request body, or payload field with a single click

Live Network Capture & Parameter Aggregator

Real-time monitoring and capturing of HTTP / XHR / Fetch requests
Automatic extraction and aggregation of parameters from headers, query strings, URL-encoded bodies, and nested JSON payloads
Inspect raw request/response headers, bodies, and response previews directly
Filter by All / XHR / Documents / POST and search by URL or method
One-click send to Tester, Replay, cURL export, and parameter copy

Payload Presets & Request Manipulation

Built-in payload preset manager with dynamic column generator for UNION-based SQLi tests
Interactive JSON body tree examiner for navigating and selecting deeply nested keys
Custom HTTP header injector (X-Forwarded-For, Authorization, custom cookies, Host rewrite, and more)
Method selection (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS), body editor, and optional page navigation
One-click cURL export of the current request

Response Viewer

Syntax highlighting for JSON and HTML response bodies
Search within the response (case-sensitive option, next/previous match)
Copy full response or body only

Multi-Format Encoder / Decoder

Live preview – encode/decode updates as you type
2-step chain – optional second encoding stage (e.g. URL → Base64 in one step)
Swap Input ↔ Output for rapid multi-pass encoding
Push results directly into Payload, URL, or Request Body
Formats include:
URL, Double URL, Triple URL, Selective URL (SQLi-focused)
Base64, Base64 URL-Safe
Hex (spaced / 0xAABB… / \x.. / 0xAA,0xBB), Binary, ASCII/Decimal
SQL CHAR(), SQL CHAR(0x…), SQL CONCAT(CHAR…)
Unicode \u, Unicode %u, Fullwidth Unicode
HTML Entities, JSON, JWT Decode (header / payload / signature), ROT13

Themes & Localization

Multiple built-in color schemes (Neon Green, Cyber Cyan, Violet, Amber, Hot Pink, Electric Blue, Matrix Lime, Mono) plus custom accent color picker
Multi-language interface: English, Deutsch, Español, Français, Português, Русский, 日本語, 中文 (preference saved)

Permissions Justification

devtools: Integrates natively into Firefox DevTools for a seamless workflow
webRequest / cookies / activeTab: Required to capture live network traffic, inspect response headers, inject payload parameters, and manage cookies for security testing

GitHub: https://github.com/blackn3x/SQLIBar
DisclaimerSQLiBar is strictly intended for authorized security testing, educational purposes, and vulnerability research on systems you own or have explicit permission to test.
Rated 5 by 1 reviewer
Log in to rate this extension
There are no ratings yet

Star rating saved

5
1
4
0
3
0
2
0
1
0
Read 1 review
Permissions and data

Required permissions:

  • Extend developer tools to access your data in open tabs
  • Access browser tabs
  • Access your data for all web sites

Optional permissions:

  • Access your data for all web sites

Data collection:

  • The developer says this extension doesn't require data collection.
Learn more
More information
Add-on Links
  • Copy add-on ID
Version
1.0.6.1
Size
169.54 kB
Last updated
19 hours ago (16 Aug 2026)
Related Categories
  • Web Development
Licence
MIT Licence
Version History
  • See all versions
Add to collection
Report this add-on
Go to Mozilla's homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Download

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

Latest Builds

  • Nightly
  • Beta

Firefox for Business

  • Enterprise

Community

  • Connect
  • Contribute
  • Developer

Follow

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike Licence v3.0 or any later version.