secretsifter / secretsifter-burp
PublicBurp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, entropy analysis, HTML reports & more.
Burp Suite extension that scans web traffic for exposed credentials, API keys, tokens, and personal data to help secure applications.
How It Works
You find this handy tool while looking for ways to spot hidden passwords and private codes in websites you're testing.
Download the file and drop it into your security scanner with a simple click—no complicated setup needed.
Flip the switch to start watching your web traffic and adjust a few friendly sliders for how picky it should be.
As you browse or test sites, hidden credentials and sensitive info light up right in your scanner's dashboard.
Paste a list of pages to scan extra carefully, following links to scripts and reports for everything found.
You get clear reports of risks, rotate the bad stuff, and make your site safe from prying eyes.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.