全部应用

retire.js
4.9
-----------------------
Scanning website for vulnerable js libraries Scan a web app for use of vulnerable JavaScript libraries. The goal of retire.js is to help you detect use of version with known vulnerabilities. Retire.js web extension isn't the original RetireJS project but is predominantly based on RetireJS opensource repo available on github - http://retirejs.github.io/retire.js/ ========== Release 1.9.0 - Adjusting severities based on github advisory data Release 1.8.9 - Fixed severity rating Release 1.8.8 - Added tableexport.jquery.plugin vuln Release 1.8.6 - Adding jquery-deparam vuln Release 1.8.5 - Update js repository Release 1.8.4 - Fixed CVE-2019-11358 Release 1.8.3 - Sync of versions with github database Release 1.8.2 - Fixed npm name of jquery.datatables Release 1.8.1 - Improved extractor for jquery.dataTables Release 1.8.0 - Added pendo vuln Release 1.7.9 - Added one more test case Release 1.7.8 - Updating vulnerability repo based on information from OSV Release 1.7.7 - Added test case for ckeditor Release 1.7.6 - Added CKEditor Vulnerable version less than 4.21.0 Release 1.7.5 - Improved Svelte detection Release 1.7.4 - Adding some more stuff and a bit of cleanup Release 1.7.3 - Updated information on known vulnerabilities Release 1.7.2 Added Ember.js prototype pollution vuln Release 1.7.1 - Adjusted the severity, from medium to high, of the vulnerabilities CVE 2022-24785 and CVE-2022-31129 Release 1.7.0 - Fixed underscore.js typo Release 1.6.9 - Fixed moment.js test Release 1.6.8 - Added jquery-ui CVE-2022-31160 Release 1.6.7 - Fixup for tinyMCE which includes dompurify Release 1.6.6 - Added next.js vulnerabilities Release 1.6.5 - Fixed uri jquery.dataTables vuln Release 1.6.4 - Added Svelte vulns Release 1.6.3 - Reported vuln for all versions of AlaSQL library Release 1.6.2 - Fixed axios typo Release 1.6.1 - Axios vulnerabilities added Release 1.6.0 - Adding plupload vulns for 3.1.4, 3.1.5, 2.3.8 and 2.3.9 Release 1.5.8 - Added CVE-2017-18214 in js report Release 1.5.6 - Added missing jquery-ui CVEs Release 1.5.5 - Added XSS vulnerabilities for CKEditor Release 1.5.4 - Added medium vuln for plupload below 2.3.7 and below 3.1.3 Release 1.5.3 - Removed errors in the reports Release 1.5.2 - I updated all of the mismatching severities based on NIST Release 1.5.1 - Additional error handling Release 1.5.0 - Fixed some bugs to recognize vulnerable js libs Release 1.4.9 - Added additional Bootstrap's file content extractor Release 1.4.8 - Fixed incorrect tinyMCE vuln version Release 1.4.7 - Added some missing vulns to json repo Release 1.4.6 - Changed summary for jquery.ui.tooltip related vulnerability Release 1.4.5 - CVE specified for jQuery.htmlPrefilter Release 1.4.0 - Added CVE-2020-7676 for angular < 1.8.0 Release 1.3.8 - Added possibility of showing unknowns Release 1.3.7 - Reports XSS in jQuery < 3.5.0 Release 1.3.6 - changed handlebars.js -> handlebars in jsrepository.json Release 1.3.5 - Fixed bug: Handlebars not detected properly in newer versions Release 1.3.4 - Adds some missing vulns Release 1.3.3 - Added popular bootstrap's uri extractor Release 1.3.2 - Added some vulns Release 1.3.1 - Added jQuery mobile XSS vulnerability Release 1.3.0 - Added jQuery vulnerability as per CVE-2019-11358 Release 1.2.9 - Added two Prototype Pollution vulns in Handlebars Release 1.2.8 - Added more descriptive link for angularjs vulnerability Release 1.2.7 - Added CVE identifiers about bootstrap release below 4.3.1 and below 3.4.1 Release 1.2.6 - Fixing regex for knockout Release 1.2.5 - Updated report about bootstrap vulnerabilities Release 1.2.4 - Fixed CkEditor vuln Release 1.2.3 - Added regex for handlebars hashbang comment Release 1.2.2 - Bootstrap: clarified vulnerabilities, added CVE's (#257) Release 1.2.1. - Replaced regex to match older versions of tinyMCE (#256) Release 1.2.0 - Fixed wrong react versioning for bug Release 1.1.9 - Added ExtJS vulns Release 1.1.8 - Added vue.js vulns Release 1.1.7 - Fixed typo in repo Release 1.1.6 - Add summary for CVE-2011-4969 and link to jQuery ticket (#228) Release 1.1.5 - CkEditor xss vulnerability reported =========="
SEOInfo
4.7
-----------------------
Shows SEO issues as you navigate pages. Displays performance data and full AMP status and errors for HTML pages. SEOInfo automatically alerts you as you navigate your website of SEO-related errors. For instance: invalid canonical, hreflang, AMP version. At the click of a button, all SEO and performance information and graphs about the current page are displayed. Includes SEO checks, structured data validation, Lighthouse validation, AMP validation inside the extension. This information can be saved with a single click to another tab for printing or saving to file. SEOInfo is available in English, Spanish and French - partial Russian translation. Features: Automated checks and validation: - Core Web Vitals scores with icon alerts when out of bound - Canonical: is the canonical link valid? ie not an error, not blocked by robots.txt or a redirect loop - AMP pages: full validation. Errors and warnings are displayed in the extension (AMP-related features are not available on Firefox) - HrefLang: full validation: multiple entries, blocking by meta or robots.txt, reciprocal links, valid language, country and script variations codes. Loads all hreflang targets and run the same checks - Assets: load status (OK, 404, 403, etc) On demand checks and validation: - Structured data full validation (json+ld and microdata). Full report equivalent to that on Google online structured data tool. - Desktop and Mobile versions audit using Google Insight API - Full analysis and scoring with errors and recommendation on Performance, Accessibility, Best Practices, SEO and Progressive Web App Collected/displayed information: - Page title, description, canonical - Accurate Google search results preview with title truncating by pixel, breadcrumb and publication date representation based on JSON-LD structured data and favicon - Check if page can be indexed, followed - applying robots.txt content - Page is mobile-compatible - Chain of server-side redirects to load the page - Performance: TTFB, Interactive, First Contentful paint, Load times, transfer sizes for page and assets (images, fonts, css, javascript, ...) - Performance and resources sizes displayed in table and as graphs - Service workers with status and manifest - All links on page, with follow, no-follow, internal vs external, invalid, non-HTTP, etc - All links can be validated for HTTP status and errors - All links can be saved as Excel files with their HTTP status or redirects. - AMP status: has an AMP version, is an AMP page? - If a page as an AMP version, the AMP version is validated in the background so you do not need to visit it - All HRefLang tags with validation results - All server response headers - Server IP and HTTP protocol version used - All OGP and Twitter Cards tags - All other meta tags and links tag - All JSON-LD structured data tags - List of all assets loaded, with error/success and from server/from cache status - Assets list can be saved as Excel files with their HTTP status, size, timings, redirects. - Entire report can be saved in a different tab with a single-click and then printed or saved to a file. The extension icon changes to tell you if the current page is ok or has errors or warning. Clicking the extension icon provides you with all the details."