Back to Extensions

Untrusted Types for DevTools
5.0(0)
1,000 users
Preview
1 / 2
About this extension
Extension
Developer Tools
Abusing Trusted Types to discover XSS sinks.\n\nDiscover and test inputs passed into sinks that could lead to DOM XSS vulnerabilities.
A sink is a code pattern that could run arbitrary JavaScript code if the input is malicious, for example: innerHTML, eval, document.write.
This extension adds a panel to DevTools where you can see/filter the sink logs and customize settings.
Keywords (by default: "d0mxss") that are found to be passed in a sink will be highlighted in the extension and in console.
You can then find the stack trace of a specific log:
1. Click to copy the ID,
2. Open Console>Filter and paste the ID,
3. Now you can inspect the stack trace. Click on the function name to open it in the Sources tab.
Developer
U
Unknown Developer
Extension Info
Version
1.1.1
Updated
October 12, 2021
Size
39.16KiB
Languages
English
Users
1,000
Developer
U
Unknown Developer
Extension Info
Version
1.1.1
Updated
October 12, 2021
Size
39.16KiB
Languages
English
Users
1,000