BurpJSLinkFinder is a Burp Suite extension that performs passive scanning of JavaScript files to identify endpoint links within web applications. The extension operates by analyzing JavaScript code through both static and dynamic analysis techniques to discover potential API endpoints, URLs, and other links that may be embedded in client-side scripts. As a passive scanning tool, it automatically examines JavaScript files encountered during web application testing without requiring active interaction or modification of requests. The extension is designed to assist security researchers and developers in identifying potential attack surfaces and vulnerabilities by mapping out endpoints that might not be immediately visible through traditional web application crawling. It integrates directly into the Burp Suite platform, allowing users to leverage the discovered endpoints for further security testing and vulnerability assessment activities.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
APKiD is a tool that identifies compilers, packers, obfuscators, and other weird stuff in APK files.
An open-source tool that automates the detection and analysis of DLL hijacking vulnerabilities in Windows applications, providing detailed reports and remediation guidance.
A deliberately vulnerable Java web application designed for educational purposes to teach web application security concepts and common vulnerabilities.
A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.
ThreatLocker is an enterprise cybersecurity platform that provides comprehensive endpoint protection and zero-trust security to prevent ransomware, viruses, and other malicious software from running on endpoints.
SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.
A technology lookup and lead generation tool that identifies the technology stack of any website and provides features for market research, competitor analysis, and data enrichment.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.