Shadow DOM UI with advanced OWASP-aligned checks: v10.3 UI + v5 depth + intrusive probes (SQLi/IDOR/SSRF/Rate-limit) and heuristics (ports/cache/fingerprinting). Live summary, filters, search, export, copy, and a Settings page for wordlists and options.
ShadowSec is a Tampermonkey userscript that injects a powerful website security auditing panel directly into your browser. It's built with a modern Shadow DOM UI and runs a wide range of security checks with real-time reporting.
⚠️ This tool is intended for educational purposes and for auditing your own websites only!
<details> sections.ShadowSec merges the strict, detailed checks from earlier versions with new recon and fuzzing modules for broader coverage.
fetch/WebSocket.on*= attributes.unsafe-inline / unsafe-eval.ws:// connections.This tool is for educational purposes and auditing your own websites only.
Running it against third-party websites without permission may be illegal.
The author is not responsible for misuse.