Firefox Browser Add-ons
  • Extensions
  • Themes
    • for Firefox
    • Dictionaries & Language Packs
    • Other Browser Sites
    • Add-ons for Android
Log in
Preview of Jsmon Security Analyzer — Web Security Inspector

Jsmon Security Analyzer — Web Security Inspector by Jsmon

Capture and analyze browser traffic in real time. Detects exposed secrets, shadow APIs, and supply chain risks in JS, HTML, JSON, YAML, and 20+ file types. Powered by Jsmon.

0 (0 reviews)0 (0 reviews)
34 Users34 Users
Download Firefox and get the extension
Download file

Extension Metadata

Screenshots
Jsmon.sh Home PageResponse headers in ReconnaissanceS3 buckets in ReconnaissanceScan Options in Jsmon
About this extension
Jsmon Security Analyzer — Browser Extension

Automatically capture and analyze web traffic directly from your browser.
Every JavaScript file, API response, config, and document is sent to
Jsmon's External Attack Surface Management (EASM) engine for real-time
security analysis — no manual uploads, no proxies required.

What it detects
  • Exposed secrets — API keys, tokens, credentials leaked in JS or config files
  • Shadow APIs — undocumented or forgotten endpoints buried in frontend code
  • Supply chain risks — vulnerable or suspicious NPM packages loaded at runtime
  • Sensitive data exposure — PII, internal paths, environment variables
  • Misconfigured assets — insecure headers, open redirects, debug artifacts

Supported file types

JS · JSX · TS · HTML · PHP · ASPX · CFG · YAML · JSON · XML · ENV ·
INI · TXT · CSV · LOG · SQL · GRAPHQL · WASM · MAP · and more (20+ extensions)

How it works
  1. Install the extension and connect your Jsmon account
  2. Browse normally — the extension passively captures traffic
  3. Matched file types are forwarded to Jsmon for deep analysis
  4. View findings in your Jsmon dashboard: secrets, APIs, risks, asset inventory

Who it's for
  • Security engineers running recon or pen tests on web applications
  • AppSec & EASM teams monitoring their organization's external attack surface
  • Bug bounty hunters accelerating JS recon workflows
  • CISOs & compliance teams enforcing continuous visibility across web assets

About Jsmon

Jsmon is an AI-powered External Attack Surface Management platform trusted
by security teams worldwide. Built by practitioners, for practitioners.

🔗 jsmon.sh
Rated 0 by 0 reviewers
Log in to rate this extension
There are no ratings yet

Star rating saved

5
0
4
0
3
0
2
0
1
0
No reviews yet
Permissions and data

Required permissions:

  • Access browser tabs
  • Access your data for all websites
Learn more
More information
Add-on Links
  • Homepage
  • Support site
  • Support Email
  • Copy add-on ID
Version
1.5
Size
2.05 MB
Last updated
2 days ago (Jun 3, 2026)
Related Categories
  • Web Development
  • Privacy & Security
License
MIT License
Version History
  • See all versions
Tags
  • security
Add to collection
Report this add-on
Go to Mozilla's homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Browsers

  • Desktop
  • Mobile
  • Enterprise

Products

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike License v3.0 or any later version.