fransr/postMessage-tracker
A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3382
- days_rel: n/a
- days_push: 950
- n_releases_24m: 0
Adoption not part of the score
1335 stars · 187 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Chrome extension that tracks postMessage listener usage across a page and its subframes, showing listener counts via the extension icon and logging URL, domain, and stack traces. It unpacks common wrappers (Raven, New Relic, Rollbar, Bugsnag, jQuery) and can send logs to a configurable endpoint for later review.
Use cases
- find hidden postMessage listeners in iframes during a bug bounty
- audit which domains a page communicates with via postMessage
- debug cross-window messaging between frames
- log postMessage listener functions and stack traces to an endpoint
- bypass error-tracking wrappers to see real listeners in devtools
When to choose
- you are doing web security research or bug bounty hunting on postMessage handlers
- you need to trace short-lived or interaction-triggered listeners across subframes
When to avoid
- you need automated postMessage security testing in CI rather than manual browser inspection
- you use a browser other than Chrome
Facets
plugin · maturity maintenance
security developer-tools monitoring security browser-extensions developer-tools web-development browser browser-extension postmessage chrome-extension penetration-testing web-security devtools bug-bounty javascript
1 source
- readme: https://github.com/fransr/postMessage-tracker · fetched 2026-08-28 · 16c7610b31e5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| fransr/postMessage-tracker | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="fransr/postMessage-tracker")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem