JSHarvest di hawtsauce
Inventory every JavaScript file a page loads — deduplicated and classified first- vs third-party — with source-map recovery, hidden-chunk discovery, risk flags and export to TXT, JSON, CSV, HAR or a wordlist.
Disponibile in Firefox per AndroidDisponibile in Firefox per Android
Scansiona il codice QR per aprire questa estensione in Firefox per Android
Metadati estensione
Screenshot
Informazioni sull’estensione
JSHarvest builds a complete, deduplicated inventory of the JavaScript running on any page you visit. Everything is processed locally in your browser — no analytics, no telemetry, no account.
What it captures
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
What it captures
- Network requests, DOM sources (script tags, preloads, module preloads, import maps, inline references) and Worker / ServiceWorker registrations — merged into one deduplicated list.
- Classification for every file: first-party vs third-party, bundler output, source maps, and the vendor behind it (Google, Meta, Stripe, Sentry and many more).
- Risk flags: third-party scripts loaded without Subresource Integrity, mixed content, and failed or 4xx responses.
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
Voto 0 da 0 revisori
Permessi e dati
Permessi obbligatori:
- Consentire agli strumenti di sviluppo accesso ai dati delle schede aperte
- Accedere alle schede
- Accedere alle attività durante la navigazione
- Accedere ai dati di tutti i siti web
Permessi facoltativi:
- Accedere ai dati di tutti i siti web
Raccolta dati:
- Lo sviluppatore dichiara che questa estensione non richiede la raccolta di dati.
Raccolta dati facoltativa, secondo lo sviluppatore:
- Attività sul sito web
- Contenuto dei siti web
Ulteriori informazioni
- Link componente aggiuntivo
- Versione
- 1.1.0
- Dimensione
- 133,01 kB
- Ultimo aggiornamento
- 3 giorni fa (25 ago 2026)
- Categorie correlate
- Licenza
- Licenza MIT
- Informativa sulla privacy
- Consulta l’informativa sulla privacy per questo componente aggiuntivo
- Cronologia versioni
- Aggiungi alla raccolta