Hercules | DAST de Hercules
Powerful web application security scanner. Analyze XSS, SQLi, ports, API, S3, subdomains and more.
Metadate extensie
Capturi de ecran
Despre această extensie
Hercules DAST (Dynamic Application Security Testing) — a professional tool for web application security analysis directly in your browser.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
Evaluat cu 0 de către 0 recenzori
Permisiuni și date
Permisiuni necesare:
- Să acceseze filele browserului
- Să îți acceseze datele pentru toate site-urile web
Colectare de date:
- Dezvoltatorul spune că extensia nu necesită colectarea de date.
Mai multe informații
- Linkurile suplimentului
- Versiune
- 1.0.0
- Mărime
- 63,47 KB
- Ultima actualizare
- 9 zile în urmă (27 mart. 2026)
- Categorii conexe
- Licență
- Mozilla Public License 2.0
- Istoricul versiunilor
- Adaugă în colecție