# Eval Villain

> Hook native JavaScript functions before page load to see how a website uses them. Narrow down output based on the appearance of URL and session artifacts, user configured strings/regex, blacklists and more.

Canonical page: [https://chrome-stats.com/d/eval-villain](https://chrome-stats.com/d/eval-villain)

## Overview

- **ID:** `eval-villain`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** bemodtwz
- **Category:** web-development,privacy-security
- **Daily users:** 173
- **Weekly downloads:** 6
- **Rating:** 3.67 / 5 (3 ratings)
- **Version:** 2.11
- **Last updated:** 2024-11-13
- **First published:** 2018-08-02
- **Size:** 54 KB
- **Data as of:** 2026-09-10
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/eval-villain/)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/eval-villain/privacy/](https://addons.mozilla.org/firefox/addon/eval-villain/privacy/)

## Description

Eval Villain is a powerful Chrome extension designed to hook native JavaScript sink functions before page load, enabling users to monitor how web pages utilize these functions. It automatically hooks common DOM XSS sinks but can be customized to target any JavaScript function. With options to filter results based on URL patterns, session data, user-defined strings or regex, and blacklists, users gain precise control over output.

Beyond detecting DOM-based cross-site scripting, Eval Villain aids in analyzing webpage behavior by hooking functions like eval(), decodeURI(), and addEventListener(), unveiling potential obfuscation, hidden URL parameters, or post message handlers. Its recursive decoding capabilities help identify encoded HTML embedded in unusual locations such as the window name. This highly configurable tool is ideal for security researchers and developers aiming to understand JavaScript execution flows and identify vulnerabilities or malware. Supported by Doyensec Research, Eval Villain offers deep insight into web security through advanced JavaScript instrumentation.

## Rankings

- #8,845 — Overall
- #42 — will
- #52 — string
- #69 — configure
- #73 — fragment
- #117 — function

## Permissions and access

### Permissions

- `<all_urls>`
- `storage`

## Safety

- **Risk impact:** Moderate risk impact
- **Risk likelihood:** Low risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [Sink Hooker](https://chrome-stats.com/d/sink-hooker) — 1 users
- [NoEval - Disable Eval()](https://chrome-stats.com/d/noeval-disable-eval) — 1 users, 3.00 / 5
- [Tracy](https://chrome-stats.com/d/tracyplugin) — 5 users, 5.00 / 5
- [DOMLogger++](https://chrome-stats.com/d/domloggerpp) — 271 users, 5.00 / 5
- [Shark Javascript Injector](https://chrome-stats.com/d/shark-javascript-injector) — 31 users, 5.00 / 5
- [Web Explode](https://chrome-stats.com/d/web-explode) — 19 users, 5.00 / 5
- [Tinker Tester Developer Spy](https://chrome-stats.com/d/tinker-tester-developer-spy) — 2 users, 4.60 / 5
- [DOM XSS Highlighter — Pro](https://chrome-stats.com/d/dom-xss-highlighter-pro) — 4 users
- [Quick Eval](https://chrome-stats.com/d/quick-eval) — 26 users
- [Code Injectrtor](https://chrome-stats.com/d/code-injectrtor)
- [EventSentinel](https://chrome-stats.com/d/eventsentinel)
- [Epupp: Live Tamper your Web](https://chrome-stats.com/d/epupp) — 20 users, 5.00 / 5

---

Source: [Chrome-Stats](https://chrome-stats.com/d/eval-villain)
