# React2shell - RSC Sentinel

> A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in web applications.

Canonical page: [https://chrome-stats.com/d/react2shell-rsc-sentinel](https://chrome-stats.com/d/react2shell-rsc-sentinel)

## Overview

- **ID:** `react2shell-rsc-sentinel`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Muhammad Uwais
- **Category:** privacy-security
- **Daily users:** 122
- **Weekly downloads:** 12
- **Rating:** 5.00 / 5 (1 ratings)
- **Version:** 1.1
- **Last updated:** 2026-02-13
- **First published:** 2026-02-03
- **Size:** 167 KB
- **Data as of:** 2026-09-15
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/react2shell-rsc-sentinel/)

## Description

Overview

RSC Sentinel is a Firefox browser extension for security researchers and educators who want to observe React Server Components (RSC) and Next.js App Router indicators while browsing. It focuses on passive detection by default, highlighting potential signals without altering site behavior. For authorized assessments, it also offers optional manual tools for active probing and controlled command execution initiated by the user.

Features
<ul><li><strong>Passive Detection</strong>: Automatically watches for high-level RSC and App Router indicators during normal browsing.</li><li><strong>Active Probing</strong>: Allows a user-initiated fingerprint request to gather additional signals in a controlled manner.</li><li><strong>Manual Command Execution</strong>: Provides a manual, user-driven execution workflow intended strictly for authorized testing.</li></ul>
How Detection Works (High-Level)

RSC Sentinel evaluates a combination of runtime indicators, HTTP response headers, and response content patterns that are commonly associated with RSC and App Router behavior. Results are presented as signals and should be interpreted as indicators rather than definitive proof of vulnerability.

## Rankings

- #10,568 — Overall
- #92 — reach
- #102 — component
- #170 — associate
- #175 — definition

## Permissions and access

### Permissions

- `activeTab`
- `scripting`

### Host permissions

- `<all_urls>`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** Moderate risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [JS Recon & Secret Scanner](https://chrome-stats.com/d/js-recon-secret-scanner) — 7 users
- [JS Recon Buddy](https://chrome-stats.com/d/js-recon-buddy) — 166 users, 5.00 / 5
- [CSS Sentry](https://chrome-stats.com/d/css-sentry) — 2 users
- [Script Sentinel - CSP Generator](https://chrome-stats.com/d/script-sentinel-csp-generator)
- [ReconLens - Passive Security Scanner](https://chrome-stats.com/d/reconlens) — 1 users
- [Dependency Security Scanner](https://chrome-stats.com/d/dependency-security-scanner) — 1 users
- [Jsmon Security Analyzer — Web Security Inspector](https://chrome-stats.com/d/jsmon-extension) — 33 users
- [XSS Finder ext](https://chrome-stats.com/d/xss-finder-ext) — 3 users
- [Sentinel Shield](https://chrome-stats.com/d/sentinel-shield) — 1 users
- [Retire.JS Pro](https://chrome-stats.com/d/retire-js-pro) — 26 users
- [Sentinel Shield](https://chrome-stats.com/d/sentinelshield) — 1 users
- [CSRF Request Checker](https://chrome-stats.com/d/csrf-request-checker)

---

Source: [Chrome-Stats](https://chrome-stats.com/d/react2shell-rsc-sentinel)
