Trufflehog

Trufflehog

Sniffing out credentials

What is Trufflehog?
TruffleHog is a specialized Chrome extension aimed at enhancing digital safety and precision in pentests and code reviews. It significantly aids in identifying potential security loopholes by actively sniffing out API keys and credentials on the accessed websites. It’s an invaluable tool to ensure swift detection of potent risks that may go unnoticed or require strenuous manual effort to discover.
Merlin
Stats
By: dylan
Users: 7,000+
Version: 0.0.1 (Last updated: 2021-09-21)
Creation date: 2021-09-20
Risk impact: High risk impact
Risk likelihood: Low risk likelihood
Manifest version: 2
Permissions:
  • https://*/*
  • http://*/*
  • activeTab
  • tabs
  • storage
Size: 35.44K
URLs: Website
Stats date:

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.
Chrome-Stats extension
Merlin
Summary

The TruffleHog chrome extension looks for API keys and credentials on websites visited, and alerts you if there are any present. This is useful for doing pentests and code reviews, because it helps identify keys that would otherwise either be missed or have to be searched for manually

User reviews
api keys exposed
by Paranjay Singh Paranjay Singh, 2024-04-20

perfect
by error fiat error fiat, 2024-01-15

easy to grep. ;)
View all user reviews
Safety
Risk impact

Trufflehog is risky to use as it requires a number of sensitive permissions that can potentially harm your browser and steal your data. Exercise caution when installing this extension. Review carefully before installing. We recommend that you only install Trufflehog if you trust the publisher.

Risk likelihood

Trufflehog has earned a fairly good reputation and likely can be trusted.

Upgrade to see risk analysis details
Screenshots
Similar extensions

Here are some Chrome extensions that are similar to Trufflehog: