Tamper Dev

Allows you to intercept and edit HTTP/HTTPS requests and responses.

Tamper Data

View and modify HTTP requests before they are sent.

Spy Extension

This Chrome extension will read literally everything it can.

Fiddler Everywhere

Web debugging proxy for MacOS, Windows, and Linux.

A shiny new copy of Chromium that will bring colors in your hunt.

A Firefox/Burp Suite extension that provide usefull tools for your security audit.

An extension for checking if .git is exposed in visited websites.

Firefox plugin that lists Amazon S3 Buckets found in requests.

A PostMessage fuzzing extension for Chrome.

A Chrome Extension to track postMessage usage (url, domain and stack).

DOM based XSS finder

Chrome extension that finds DOM based XSS vulnerabilities.

XSS Radar

A Chrome extension for fast and easy XSS fuzzing.

Assists with finding all sinks and sources of a webapp and display the results in a nice way.

The Browser Exploitation Framework is a penetration testing tool that focuses on the web browser.

Online XSS tool with demonstration of vulnerability.