ExposedGuard 0xS0B מאת
Checks whether the sites you visit publicly expose their .git directory, .env files, or references to them, and warns you or saves them for you incase you miss them on your pentest.
זמין ב־Firefox עבור ™Androidזמין ב־Firefox עבור ™Android
יש לסרוק את קוד ה־QR כדי לפתוח הרחבה זו ב־Firefox עבור Android
נתוני העל של ההרחבה
על אודות הרחבה זו
ExposedGuard checks whether the websites you visit accidentally expose sensitive files to the public and warns you the moment it finds one.
Every time you load a page, ExposedGuard quietly probes the site for around 50 well-known file paths that developers frequently leave exposed by mistake: version control data (.git/HEAD, .git/config, .git/index, .svn/entries, .hg/), environment files (.env and its common variants like .env.production, .env.backup), credentials (.aws/credentials, .netrc, .htpasswd, SSH private keys, SFTP configs), leaked source backups (wp-config.php.bak, config.php~), backup archives (backup.zip, site.tar.gz), database dumps (db.sql, dump.sql), and debug leftovers (phpinfo.php, server-status, .DS_Store).
Unlike simple scanners, ExposedGuard validates every response, checking magic bytes, file signatures, and content patterns, so SPA catch-all routes and custom error pages don't produce false alarms. Probes run without cookies, detecting exactly what an anonymous visitor could access.
When something is found, a red badge counts the exposures on the toolbar icon, and you get a desktop notification. The popup shows each finding color-coded by severity with a content preview, lets you re-check a site manually, and keeps a history of all sites with findings. A built-in page scanner also spots references to .git and .env hidden in page source.
Privacy: ExposedGuard collects and transmits no data whatsoever. All checks happen locally, and findings never leave your browser.
Use responsibly: only probe sites you own or are authorized to test, and report exposures to the site owner.
Every time you load a page, ExposedGuard quietly probes the site for around 50 well-known file paths that developers frequently leave exposed by mistake: version control data (.git/HEAD, .git/config, .git/index, .svn/entries, .hg/), environment files (.env and its common variants like .env.production, .env.backup), credentials (.aws/credentials, .netrc, .htpasswd, SSH private keys, SFTP configs), leaked source backups (wp-config.php.bak, config.php~), backup archives (backup.zip, site.tar.gz), database dumps (db.sql, dump.sql), and debug leftovers (phpinfo.php, server-status, .DS_Store).
Unlike simple scanners, ExposedGuard validates every response, checking magic bytes, file signatures, and content patterns, so SPA catch-all routes and custom error pages don't produce false alarms. Probes run without cookies, detecting exactly what an anonymous visitor could access.
When something is found, a red badge counts the exposures on the toolbar icon, and you get a desktop notification. The popup shows each finding color-coded by severity with a content preview, lets you re-check a site manually, and keeps a history of all sites with findings. A built-in page scanner also spots references to .git and .env hidden in page source.
Privacy: ExposedGuard collects and transmits no data whatsoever. All checks happen locally, and findings never leave your browser.
Use responsibly: only probe sites you own or are authorized to test, and report exposures to the site owner.
מדורג 0 על־ידי 0 סוקרים
הרשאות ונתונים
הרשאות נדרשות:
- הצגת התרעות
- גישה ללשוניות
- גישה לפעילות הדפדפן במהלך הניווט
- גישה לנתונים שלך מכל האתרים
איסוף נתונים:
- המפתח אומר שהרחבה זו אינה דורשת איסוף נתונים.
מידע נוסף
- קישורים לתוספת
- גרסה
- 1.2.1
- גודל
- 22.71 ק״ב
- עדכון אחרון
- לפני 6 ימים (28 אוג׳ 2026)
- קטגוריות קשורות
- היסטוריית הגרסאות
- הוספה לאוסף