# nsonaniya2010/SubDomainizer

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Repository: https://github.com/nsonaniya2010/SubDomainizer
Canonical: https://ross.abutalabs.com/products/subdomainizer
Language: Python
License: MIT
License Family: permissive
Topics: python3, security-tools, security-automation, security, subdomain-scanner, subdomain-enumeration, s3-bucket, find-subdomains, cloud-storage-services, external-javascripts, secrets, secretfinder, bugbounty, find-secrets, s3-buckets, bug-bounty, madeinindia
Last push: 2026-08-11T12:35:09+00:00

## Health v2 (maintenance only)
Score: 66/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 8, longevity 100
- inputs: {"age_days": 2844, "days_push": 22, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1886, forks 235 (observed 2026-08-28T04:05:49.041281+00:00)

## What it is
SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local folders. It also detects exposed cloud storage resources like S3 buckets and CloudFront distributions that may be vulnerable to takeover.

## Use cases
- find subdomains hidden in external javascript files
- discover secrets and api keys in web pages and js files
- enumerate subdomains via certificate transparency logs
- find open s3 buckets and cloudfront urls for takeover
- bug bounty reconnaissance on a target domain
- scan a local folder of files for leaked secrets

## When to choose
- you need subdomain and secret discovery from JS files in one tool
- you want passive enumeration via crt.sh and Wayback Machine without extra setup
- you're doing bug bounty or attack-surface reconnaissance
- you need JSON output to pipe into other security tooling

## When to avoid
- you need a full active subdomain brute-forcer with wordlists
- you require high-accuracy secret detection with no false positives (feature is beta)
- you need a GUI or continuous monitoring service
- you need scanning beyond web/JS/GitHub sources

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, web-scraping, osint, vulnerability-scanning, parser
- domain: security, penetration-testing, osint, developer-tools
- platform: python, cli, windows, cross-platform
- tags: subdomain-enumeration, secret-finding, bug-bounty, recon, javascript-analysis, s3-buckets, cloud-storage, shannon-entropy, certificate-transparency, command-line, linux, macos

## Member repositories
- nsonaniya2010/SubDomainizer (main) score 66

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:49.041281+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:13:35.296510+00:00, confidence not recorded.
  - readme: https://github.com/nsonaniya2010/SubDomainizer (fetched 2026-08-28T04:05:49.041281+00:00, sha 982372e75a0a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
