Ross ROSS = Recommend OSS · open-source software intelligence for agents

shuanx/BurpAPIFinder

攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。 observed · 2026-08-28

github.com/shuanx/BurpAPIFinder · Java observed · 2026-08-28

Health v2 · maintenance only

15/100

  • Activity 0
  • Release rhythm 8
  • Longevity 62

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 881
  • days_rel: n/a
  • days_push: 700
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1472 stars · 78 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API endpoints, sensitive information leaks, and unauthorized/privilege-escalation access points. It integrates fingerprint libraries from HaE, APIKit, and sweetPotato, and supports active endpoint probing with customizable sensitive keywords.

Use cases

  • find sensitive information leaked in javascript files during a pentest
  • discover unauthorized API endpoints that expose credentials
  • detect leaked cloud access keys and secret keys in web traffic
  • enumerate user information or password change endpoints
  • find hidden admin backend login URLs
  • extract and probe API paths from JS files during red team engagements

When to choose

  • you are doing offensive security work or red team exercises with Burp Suite
  • you want passive sensitive-info detection integrated into your proxy traffic
  • you need a free alternative combining HaE, APIKit, and sweetPotato fingerprints

When to avoid

  • you need a standalone scanner outside Burp Suite
  • you require a maintained project with a formal license for compliance-sensitive environments
  • you need non-JVM tooling or CI-based automated scanning

Facets

plugin · maturity active

security vulnerability-scanning web-scraping developer-tools security penetration-testing web-development browser-extensions jvm burp-suite-extension sensitive-information-detection unauthorized-access api-discovery offensive-security red-team burp-suite

1 source

Member repositories

RepositoryRoleHealth v2
shuanx/BurpAPIFindermain15

For agents

markdown · JSON · MCP: product_card(name="shuanx/BurpAPIFinder")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem