shuanx/BurpAPIFinder
攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。 observed · 2026-08-28
Health v2 · maintenance only
15/100
- Activity 0
- Release rhythm 8
- Longevity 62
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 881
- days_rel: n/a
- days_push: 700
- n_releases_24m: 0
Adoption not part of the score
1472 stars · 78 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API endpoints, sensitive information leaks, and unauthorized/privilege-escalation access points. It integrates fingerprint libraries from HaE, APIKit, and sweetPotato, and supports active endpoint probing with customizable sensitive keywords.
Use cases
- find sensitive information leaked in javascript files during a pentest
- discover unauthorized API endpoints that expose credentials
- detect leaked cloud access keys and secret keys in web traffic
- enumerate user information or password change endpoints
- find hidden admin backend login URLs
- extract and probe API paths from JS files during red team engagements
When to choose
- you are doing offensive security work or red team exercises with Burp Suite
- you want passive sensitive-info detection integrated into your proxy traffic
- you need a free alternative combining HaE, APIKit, and sweetPotato fingerprints
When to avoid
- you need a standalone scanner outside Burp Suite
- you require a maintained project with a formal license for compliance-sensitive environments
- you need non-JVM tooling or CI-based automated scanning
Facets
plugin · maturity active
security vulnerability-scanning web-scraping developer-tools security penetration-testing web-development browser-extensions jvm burp-suite-extension sensitive-information-detection unauthorized-access api-discovery offensive-security red-team burp-suite
1 source
- readme: https://github.com/shuanx/BurpAPIFinder · fetched 2026-08-28 · d60f59f4a214
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| shuanx/BurpAPIFinder | main | 15 |
For agents
markdown · JSON · MCP: product_card(name="shuanx/BurpAPIFinder")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem