JSHarvest 作者: hawtsauce
Inventory every JavaScript file a page loads — deduplicated and classified first- vs third-party — with source-map recovery, hidden-chunk discovery, risk flags and export to TXT, JSON, CSV, HAR or a wordlist.
扫码在 Android 版 Firefox 中打开此扩展
扩展元数据
屏幕截图
关于此扩展
JSHarvest builds a complete, deduplicated inventory of the JavaScript running on any page you visit. Everything is processed locally in your browser — no analytics, no telemetry, no account.
What it captures
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
What it captures
- Network requests, DOM sources (script tags, preloads, module preloads, import maps, inline references) and Worker / ServiceWorker registrations — merged into one deduplicated list.
- Classification for every file: first-party vs third-party, bundler output, source maps, and the vendor behind it (Google, Meta, Stripe, Sentry and many more).
- Risk flags: third-party scripts loaded without Subresource Integrity, mixed content, and failed or 4xx responses.
Deep Scan (optional)
Statically analyses first-party bundles — never executing them — to reveal chunks that were never requested, rebuild the original source file tree from source maps, and surface exposed API keys or internal endpoints. Secret values are masked in the interface.
Compare and export
Save a snapshot and use Diff mode to see exactly which scripts were added, removed or changed after a deploy. Export the result as TXT, JSON, CSV, Markdown, HAR, a curl probe script, or a wordlist for further testing.
DevTools panel
A wider, sortable table under a JSHarvest tab in DevTools, better suited to large sites.
AI analysis (optional, bring your own key)
If you supply your own API key from Anthropic, OpenAI, Google Gemini, Groq or OpenRouter, JSHarvest can produce a written assessment of the page's JavaScript surface. This feature is off by default; the extension is fully functional without it, and no key means nothing is ever transmitted.
Deep Scan requests files from the site you are inspecting. Please use it only on sites you own or are authorized to test
You can also find this extension on GitHub : https://github.com/abdulhalimaltuntas/JSHarvest/
评分 5(1 位用户)
权限与数据
必要权限:
- 让开发者工具可以存取您打开的标签页中的数据
- 获取浏览器标签页
- 获知浏览器导航时的行为状态
- 访问您在所有网站的数据
可选权限:
- 访问您在所有网站的数据
收集的数据:
- 开发者称此扩展无需收集数据。
根据开发者所述,可选的数据收集有:
- 网站活动
- 网站内容
更多信息