# XSS Finder ext

> Client-side, read-only detector for common XSS risk indicators: unsafe inline JS, reflected params, javascript: URLs, lax CSP, and more.

Canonical page: [https://chrome-stats.com/d/xss-finder-ext](https://chrome-stats.com/d/xss-finder-ext)

## Overview

- **ID:** `xss-finder-ext`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** xss-finder-ext
- **Category:** other
- **Daily users:** 3
- **Version:** 1.0.0
- **Last updated:** 2025-08-27
- **First published:** 2025-08-24
- **Size:** 19 KB
- **Data as of:** 2026-09-10
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/xss-finder-ext/)
- **Website:** [https://789winner.net](https://789winner.net/)

## Description

XSS Risk Detector is a lightweight Firefox extension that helps you identify common cross-site scripting (XSS) risk indicators while browsing. It performs a safe, client-side, read-only scan of the current page—no data leaves your browser.

## Rankings

- #57,356 — Overall
- #163 — finder

## Permissions and access

### Permissions

- `activeTab`
- `tabs`
- `contextMenus`
- `storage`
- `<all_urls>`
- `webRequest`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
- This extension website URL may be invalid

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [XSS Finder](https://chrome-stats.com/d/xss-finder) — 9 users
- [XSS Detector](https://chrome-stats.com/d/xss-detector) — 2 users
- [SurfSafe](https://chrome-stats.com/d/surfsafe) — 1 users
- [SQL Injection Finder ext](https://chrome-stats.com/d/sql-injection-finder-ext) — 2 users
- [DOM XSS Highlighter — Pro](https://chrome-stats.com/d/dom-xss-highlighter-pro) — 4 users
- [CSS Sentry](https://chrome-stats.com/d/css-sentry) — 1 users
- [Cross-Origin Resource](https://chrome-stats.com/d/cross-origin-resource) — 3 users
- [XSSpect](https://chrome-stats.com/d/xsspect) — 50 users
- [KNOXSS Community Edition](https://chrome-stats.com/d/knoxss-community-edition) — 255 users, 4.00 / 5
- [Clickjacking Checker](https://chrome-stats.com/d/clickjacking-checker) — 34 users, 5.00 / 5
- [Tracy](https://chrome-stats.com/d/tracyplugin) — 5 users, 5.00 / 5
- [XSSRush](https://chrome-stats.com/d/xssrush) — 26 users, 4.00 / 5

---

Source: [Chrome-Stats](https://chrome-stats.com/d/xss-finder-ext)
