QuickAudit — web security checklist Firefox

QuickAudit — web security checklist

제작자: BAB Studios Add-on
Ten-point OWASP-style security checklist for the page you're on: headers, cookies, mixed content, exposed files, JS library CVEs.
xHeader
Modify request and response headers. No ads, no malware.

특징 및 기능

A pre-pentest sanity check that takes five seconds instead of fifteen minutes.

Before you pay for a penetration test — or before you ship — there's a set of boring, mechanical misconfigurations that show up on a depressing share of production sites. No HSTS. No CSP. Session cookies without HttpOnly. A .git directory served to the public internet. jQuery 1.8 with four known XSS advisories.

Finding these today means running curl -I, squinting at headers you half-remember, checking DevTools for mixed content, and pasting library versions into a CVE search. That's fifteen minutes per site, so people skip it, so it ships broken.

QuickAudit is that checklist, as one button.

The ten checks:

  1. Transport security — HTTPS, plus HSTS with max-age
  2. Content-Security-Policy — present, enforcing, and not defeated by 'unsafe-inline' / 'unsafe-eval' / wildcards
  3. Clickjacking protection — CSP frame-ancestors or X-Frame-Options
  4. MIME-sniffing — X-Content-Type-Options: nosniff
  5. Referrer & Permissions policy — flags policies that leak full URLs to third parties
  6. Cookie security flags — Secure, HttpOnly on session cookies, explicit SameSite
  7. Mixed content — http:// subresources on an HTTPS page
  8. JavaScript libraries with known CVEs — versions read from live page globals, looked up against OSV.dev
  9. Exposed sensitive files — /.env, /.git/HEAD, etc. (Off by default)
  10. Server version disclosure — banners that hand attackers your exact build number

Privacy: QuickAudit sends exactly one kind of data off your machine: detected library name@version strings, to api.osv.dev, to look up known CVEs. No URLs. No page content. No cookie values — the code reads cookie flags and deliberately discards values. No analytics. No account. No telemetry.

Source: https://github.com/BAB78/quickaudit

사용자 증가 및 다운로드 통계

Manifest V3 Add-on
제작자:
BAB Studios
일일 사용자:
1
버전:
1.0.0 마지막 업데이트: 2026-08-04
버전 코드:
6388847
생성 날짜:
2026-08-01
Firefox 부가 기능 GUID:
quickaudit@babstudios.dev
Firefox 부가 기능 숫자 ID:
3047304
Android용 Firefox:
아니요
위험:
Low risk impact High risk likelihood
권한:
크기:
64.40KB
이메일:
be*****@outlook.com
URL:
웹사이트 ,개인정보 보호정책
전체 설명:
자세한 설명 보기
소스:
Firefox 부가 기능 스토어
데이터 수집일:
2026-09-06
통계 및 순위 비교:

개발자에게 문의

Chrome-Stats는 이 Firefox 부가 기능을 소유하지 않습니다. 아래 정보를 사용하여 Firefox 부가 기능 개발자에게 문의하세요.
에 의해 개발:
BAB Studios
Firefox 부가 기능 스토어
https://addons.mozilla.org/firefox/addon/quickaudit-web-security/
메일 주소:
be*****@outlook.com
웹사이트:
https://github.com/BAB78/quickaudit

QuickAudit — web security checklist는 안전한가요?

위험 영향도
위험 영향도는 확장 프로그램이 접근할 수 있는 추가 권한의 수준을 측정합니다. 낮은 위험 영향도의 확장 프로그램은 많은 해를 끼칠 수 없지만, 높은 위험 영향도의 확장 프로그램은 비밀번호 도용, 보안 설정 우회, 개인 데이터 접근 등 많은 피해를 줄 수 있습니다. 높은 위험 영향도의 확장 프로그램이 반드시 악의적인 것은 아닙니다. 그러나 악의적으로 변한다면 매우 해로울 수 있습니다.

QuickAudit — web security checklist은(는) 매우 최소한의 권한만 요구합니다.

위험 영향도 분석 세부 정보
  • Medium Allows management of download operations but generally doesn't severely affect security unless misused.
위험 가능성
위험 가능성은 Firefox 부가 기능이(가) 악의적으로 변할 가능성을 측정합니다. 이는 Firefox 부가 기능 스토어에서의 게시자와 Firefox 부가 기능 평판, Firefox 부가 기능이(가) 존재한 기간, 그리고 Firefox 부가 기능에 관한 다른 신호들에 의해 결정됩니다. 우리의 알고리즘은 완벽하지 않으며, 악의적인 확장 프로그램을 탐지하는 새로운 방법을 발견함에 따라 변경될 수 있습니다. Firefox 부가 기능을(를) 설치할 때는 항상 주의하는 것이 좋습니다.

QuickAudit — web security checklist은(는) 최근에 추가되었으며, 위험 수준을 정확하게 평가하기에 충분한 데이터를 수집할 만큼 오래 존재하지 않았습니다.

위험 가능성 분석 세부 정보
  • High This extension has low user count. Unpopular extensions may not be stable or safe.
  • Medium **** ********* *** ******* ** *** **** * ******* *** ******* *** *** ** ****** ** *****
  • Medium **** ********* *** ***** ** *** **** * ******* *** ********** *** *** ** ****** ** *****
Extension Guard
확장 경비대

Extension Guard로 사용 중인 모든 확장 프로그램을 발견하고, 위험을 분석하며, 차단 정책을 적용하세요

브라우저를 안전하게 하세요
전체 위험 분석 세부 정보를 보려면 업그레이드하세요

최고의 QuickAudit — web security checklist 대안

다음은 QuickAudit — web security checklist과(와) 유사한 Firefox add-on입니다: