Advanced Client-Side Prototype Pollution Scanner
-
Updated
Aug 17, 2026 - Go
Advanced Client-Side Prototype Pollution Scanner
精选不同站点的JS逆向实例,内含详细讲解,并辅以知识点概括、加密算法、难度对比与链接跳转。涵盖补环境、扣JS、webpack与瑞数等诸多难点
☔️A curated list of tools, articles & resources to help take your frontend security to the next level. Feel free to contribute!
Get and extract the frontend code of a SPA, finding all chunks and recreating the original code from source maps. Should support common webpack/vite configurations, but note it's still experimental.
Luvv-MCP 是一个 AI 原生的前端安全分析引擎,接入 Claude Code 后,你说一句"帮我审计这个网站",AI 就能自动完成技术栈识别(1.8 万条规则覆盖 CMS/框架/CDN/中间件)、泄露扫描(阿里云 AK、GitHub Token、Webhook、JWT 等 60+ 类敏感信息)、漏洞审计(XSS、开放重定向、CSRF、IDOR、硬编码密码 6 类自动检测)、产品指纹识别(HTTP 响应头/Body/Favicon Hash 多维匹配),还能自动发现 SourceMap 并还原混淆源码。核心价值:把 SRC 挖洞和授权渗透中"人工看 JS 源码找漏洞"的环节从 30 分钟压缩到 30 秒,一行 JSON 配置即可使用。
A client-side web security tool that sanitizes potentially malicious HTML and JavaScript input by stripping unsafe tags and event attributes. Designed to demonstrate XSS prevention concepts, safe input handling, and frontend security practices using pure HTML, CSS, and JavaScript in a beginner-friendly interface.
hat is a powerful tool designed to provide secure file encryption and decryption directly within your browser. This project, primarily written in JavaScript, ensures that your sensitive data remains private by performing all encryption processes client-side, without the need for server interactions.
Demo of a secure Next.js application
Passive client-side exposure analysis platform for detecting leaked secrets, risky frontend configs, and security-relevant JavaScript patterns.
A high-performance, keyless, rule-based envelope for protecting web/API/stream data.
Next.js code obfuscation setup using webpack-obfuscator – secure and protect your production builds.
Hisec is a set of extremely intolerant server configs using CSP and headers.
Rubik is a comprehensive toolkit designed to enhance frontend security by automating common security tasks and providing valuable insights.
A high-performance reconnaissance tool built specifically for frontend web security.
🚀 Protect web data with FISE, a high-performance, keyless semantic envelope for fast, rule-based transformations and unbounded customization.
The 'CyberGuard' delivers a modular, multi-layer security system for modern web applications. It bundles client-side anomaly detection, DDoS-Guard, DOM protection, input shielding, service-worker hardening and UI blackout controls into one compact package.
Advanced terminal-based security auditing and Sensitive Data (PII) scanning tool for modern frontend architectures, SPAs, and static assets.
Client-side History API abuse, shown as a safe educational PoC
Browser tamper detection for hostile environments. Detects and blocks DevTools, automation drivers, extension injection and environment spoofing. Surfaces findings as structured risk signals, not just boolean flags.
Frontguard by Pubflow CLI scans frontend builds, public URLs, localhost apps, HAR files, and interactive browser traffic for client-side exposure risks.
Add a description, image, and links to the frontend-security topic page so that developers can more easily learn about it.
To associate your repository with the frontend-security topic, visit your repo's landing page and select "manage topics."