WebExplode

WebExplode

ID: gicnecpnnaamojhobjdgldjlbgjcoage

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
3.0.0
Size
0.08 MB
Rating
5.0/5
Reviews
1
Users
12
Type
Extension
Updated
Apr 26, 2026
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
macallantherootView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
2
Obsolete
0
Listed
2
Unlisted
0
Total Users
18
Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5

Ultimate Pentest Suite.

WebExplode is an all-in-one web application security testing and bug bounty suite built directly into your browser. Designed for cybersecurity professionals and penetration testers, it streamlines security assessments by providing tools for payload injection (XSS, SQLi, SSRF, LFI), real-time data decoding/encoding, technology fingerprinting, session/storage analysis, and passive exposure detection. Install WebExplode to centralize your security testing workflow, easily generate CSRF proofs-of-concept, bypass client-side WAFs using custom headers, and scrape sensitive endpoints or secrets from JavaScript files without ever leaving the active tab. All processes run locally in your browser to ensure maximum privacy and security during your assessments.

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://cirt.net/*
Host
Medium
Host permission — access limited to this URL pattern.
https://crt.sh/*
Host
Medium
Host permission — access limited to this URL pattern.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
URLs
30
IPv4
4
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

attacker.com-https://attacker.com/?c=
169.254.169.254/latest/meta-data/http://169.254.169.254/latest/meta-data/
169.254.169.254/latest/meta-data/iam/security-credentials/http://169.254.169.254/latest/meta-data/iam/security-credentials/
http:-http://fd00:ec2::254/latest/meta-data/
metadata.google.internal/computeMetadata/v1/http://metadata.google.internal/computeMetadata/v1/
169.254.169.254/metadata/instancehttp://169.254.169.254/metadata/instance?api-version=2021-02-01
localhost/adminhttp://localhost/admin
127.0.0.1-http://127.0.0.1/
0.0.0.0-http://0.0.0.0/
http:-http://[::1
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

10.10.14.7
IPv4
-
169.254.169.254
IPv4
-
127.0.0.1
IPv4
-
0.0.0.0
IPv4
-
Version
Size
Is Malicious
Findings
Permhash
3.0.0
Latest
0.08 MB
Benign
—
1.0.0
0.06 MB
Benign
—
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.