Understand Software. Architecture intelligence + client-side security for any web app, right in your browser. Local-first Chrome (MV3) extension.
-
Updated
Aug 22, 2026 - TypeScript
Understand Software. Architecture intelligence + client-side security for any web app, right in your browser. Local-first Chrome (MV3) extension.
An educational phishing simulation login page demonstrating how fake UIs capture user credentials. It logs inputs, stores them locally, and emails the captured data for awareness training. Intended strictly for controlled, ethical use to teach URL verification and phishing prevention.
Some Generic Browser Exploits (For Educational Purposes Only)
CWE-602 客户端鉴权脆弱性白盒审计方法论与纵深防御加固研究框架
A polished, accessible client-side password strength checker that estimates entropy, detects weak patterns, and provides actionable suggestions. Includes a built-in password generator, works fully offline with no network calls, and uses ARIA live updates for accessibility. Ideal for demos, portfolios, or frontend components.
The EyalSec browser for security testing. Browse the web app you are testing and it reports DOM-XSS flows that really happened in the page: the source (URL, postMessage, storage, cookies), the sink, and the attacker-controlled characters. Linux x86_64.
Next.js code obfuscation setup using webpack-obfuscator – secure and protect your production builds.
Unpacked Telegram web app for research.
The 'CyberGuard' delivers a modular, multi-layer security system for modern web applications. It bundles client-side anomaly detection, DDoS-Guard, DOM protection, input shielding, service-worker hardening and UI blackout controls into one compact package.
Vollständige Webanwendung für OpenPGP-Verschlüsselung, basierend auf React, TypeScript und openpgp.js.
SMUGGLR is a browser-based Unicode steganography and text obfuscation toolkit for experimenting with invisible characters, homoglyphs, whitespace ciphers, and Unicode-based payload hiding techniques — all fully client-side with zero network calls. 🔓
ClientVault is a lightweight, in-page web security tool that lets you inspect, analyze, and manage all client-side storage used by a website — including cookies, localStorage, sessionStorage, and more. Built for developers, pentesters, and bug bounty hunters.
EntropyKey is a web application that generates unique and secure tokens using your device's camera. The randomness in the video feed helps create unpredictable tokens, making them suitable for passwords or other secure identifiers.
Bounded served-HTML script inventory for PCI payment pages. Fail CI on observed hosts outside your authorization list.
Proof of Concept (PoC) demonstrating Clickjacking vulnerability risks on the CEX.IO profile page. Web security research and UI/UX vulnerability analysis.
GlanceX is a 100% privacy-first, client-side directory search engine for Excel/CSV sheets. Fast search, offline-capable, and secured with zero-network tracking.
A zero-overhead client-side HTTPS enforcer module for Lydia CMS v1.0. Intercepts authorization events, prevents plain-text data leaks over HTTP, and includes automated multilingual test suites.
Website proptection tool beyond a captcha solver. Lightweight JavaScript site protection library that secures forms without traditional CAPTCHA challenges. Advanced client-side site protection tool that goes beyond traditional CAPTCHA by preventing automated form abuse and bot submissions.
SE·EMU is a browser-based social engineering simulation designed to help cybersecurity learners understand and practice the human side of offensive security.
AI-driven dynamic client-side encryption system. Application-layer security with language-agnostic reverse proxy, replay protection, and client-side payload validator.
To associate your repository with the client-side-security topic, visit your repo's landing page and select "manage topics."