Sniffing out credentials
What is Trufflehog?
TruffleHog is a specialized Chrome extension aimed at enhancing digital safety and precision in pentests and code reviews. It significantly aids in identifying potential security loopholes by actively sniffing out API keys and credentials on the accessed websites. It’s an invaluable tool to ensure swift detection of potent risks that may go unnoticed or require strenuous manual effort to discover.
Extension stats
By: dylan
Users: 8,000+
Rating: 5.00
(7)
Creation date: 2021-09-20
Risk impact: High risk impact
Risk likelihood: Low risk likelihood
Manifest version: 2
Permissions:
Size: 35.44K
Email: fo*****@trufflesec.com
Other platforms
Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions?
Install
Chrome-Stats extension
to view Chrome-Stats data as you browse the Chrome Web Store.
Extension summary
The TruffleHog chrome extension looks for API keys and credentials on websites visited, and alerts you if there are any present. This is useful for doing pentests and code reviews, because it helps identify keys that would otherwise either be missed or have to be searched for manually
User reviews
The popups are broken. Sometimes there are like ten of them with the same content. They block the browser until you interact with the pop-up. Notifications would work way better.
thanks for publishing this extension
api keys exposed
Extension safety
Risk impact
Trufflehog requires some sensitive permissions that could impact your browser and data security. Exercise caution before installing.
Risk likelihood
Trufflehog has earned a fairly good reputation and likely can be trusted.
Upgrade to see risk analysis details
Similar extensions
Here are some Chrome extensions that are similar to Trufflehog:
DotGit Shodan YesWeHack VDP Finder Tracy Vulners Web Scanner XSS OWASP Penetration Testing Kit FindSomething Hack-Tools CounterXSS retire.js Bishop Vulnerability Scanner
davtur19
4.83
10,000+
https://shodan.io
4.53
100,000+
acc+browserext
5.00
1,000+
jacob.heath.ncc
4.00
596
vankyver
4.55
9,000+
totofish2021
5.00
2,000+
https://pentestkit.co.uk
4.81
20,000+
ResidualLaugh
4.88
20,000+
Ludovic COULON & Riadh BOUCHAHOUA
4.63
30,000+
playarun93
5.00
529
jadwigaostrowska803
4.89
20,000+
Jack Kingsman
3.75
3,000+