20 Best Chrome Extensions for Ethical Hacking and Pentesting (2026)

By George Mutune   Published: 11/15/20   Updated: 09/26/26   12 min read

Updated September 2026. We rechecked every extension on this list against the Chrome Web Store in September 2026. Eight of the Web Store links in the original 2020 article now lead to unavailable listings, one more tool is a Manifest V2 package that current Chrome won’t run, and several others had no working listing at all. We removed them and added maintained alternatives, so the list now has 20 working extensions.

Browser extensions won’t replace a full testing proxy such as Burp Suite or OWASP ZAP. They do make everyday recon and web testing faster: fingerprinting a site’s technology, editing cookies and headers, switching proxies, encoding payloads and pulling links from a page. Everything below is free to install, and each one was live in the Chrome Web Store and built on Manifest V3 when we checked.

Use these only on systems you own or have written permission to test. Running attack payloads against other people’s sites is illegal in most countries, even if the tool is free and easy to install.

What changed since the original list

Two things forced a rewrite.

We also dropped entries we couldn’t match to a live Web Store listing (Form Fuzzer, XSS Rays, WebSecurify, Port Scanner and iMacros), plus XSS ChEF, which was a proof-of-concept exploitation framework rather than a store extension. The old article also described Tamper Data, which was a Firefox add-on, and linked it to the retired Tamper Chrome listing.

The 20 best Chrome extensions for ethical hacking at a glance

ExtensionBest forReplaces (from the old list)
WappalyzerTechnology fingerprintingKept
BuiltWith Technology ProfilerTechnology fingerprintingNew
ShodanExposed ports and servicesOpen Port Check Tool, Port Scanner
IP Address and Domain InformationDNS, ASN and hosting reconKept
Wayback MachineOld pages and forgotten endpointsNew
DotGitExposed .git and config filesBishop Vulnerability Scan
Retire.jsVulnerable JavaScript librariesNew
Link GopherExtracting links from a pageSite Spider Mark II
OWASP Penetration Testing KitAll-in-one web testingKept
HackBarManual payload testingKept
Hack-ToolsPayload and shell cheat sheetsXSS Rays, Form Fuzzer
d3coderEncoding and hashingKept
Cookie-EditorViewing and editing cookiesEditThisCookie
User-Agent Switcher and ManagerTesting device-specific behaviorNew
Talend API TesterCrafting HTTP and API requestsRequest Maker, Tamper Chrome
FoxyProxyRouting traffic to Burp or ZAPProxy SwitchySharp
Proxy SwitchyOmega 3 (ZeroOmega)Rule-based proxy switchingProxy SwitchyOmega
Clear CacheOne-click cache clearingClassic Cache Killer
Web DeveloperForms, cookies and page inspectionNew
Note AnywhereNotes on the page you’re testingKept

Reconnaissance and fingerprinting extensions

Recon, sometimes called information gathering or banner grabbing, tells you what a site runs so you can look up known vulnerabilities for those versions.

1. Wappalyzer

What it does: Identifies the content management system, web server, JavaScript frameworks, analytics tools, CDN and other technologies a site uses, often with version numbers.

How pentesters use it: A quick first look at a target. Version numbers point you to the CVEs worth checking. It was the most widely used extension on this list when we checked, with about 3 million users.

Wappalyzer on the Chrome Web Store

2. BuiltWith Technology Profiler

What it does: Another technology profiler that pulls from BuiltWith’s database, including hosting, email and advertising providers.

How pentesters use it: A second opinion when Wappalyzer misses something, especially third-party services. Its listing was last updated in 2022, but it is a Manifest V3 package and still installs.

BuiltWith Technology Profiler on the Chrome Web Store

3. Shodan

What it does: Shodan’s official extension. It shows where the current site is hosted, who owns the IP address and which other ports and services Shodan’s internet-wide scans have seen on it.

How pentesters use it: Passive port and service discovery without sending a single packet to the target yourself. It replaces the old port-scanner extensions, which are no longer available.

Shodan on the Chrome Web Store

4. IP Address and Domain Information

What it does: Shows DNS records, IP geolocation, hosting provider, ASN and routing details for the site you’re on.

How pentesters use it: Mapping who hosts a target and which other domains share its infrastructure.

IP Address and Domain Information on the Chrome Web Store

5. Wayback Machine

What it does: The Internet Archive’s official extension. It shows archived copies of the page you’re viewing.

How pentesters use it: Finding old pages, parameters and endpoints that have vanished from the live site but may still work on the server.

Wayback Machine on the Chrome Web Store

6. DotGit

What it does: Checks each site you visit for exposed .git, .svn and .hg folders, plus .env and .DS_Store files, and notifies you when it finds one.

How pentesters use it: Catching a common and serious misconfiguration: an exposed Git folder can leak source code, credentials and API keys. It covers the main job the retired Bishop Vulnerability Scan used to do.

DotGit on the Chrome Web Store

7. Retire.js

What it does: Scans pages for JavaScript libraries with known vulnerabilities, such as old versions of jQuery or AngularJS, using the Retire.js database.

How pentesters use it: Flagging outdated front-end libraries, a finding that appears in almost every web app test. The listing is published by the Retire.js project’s author.

Retire.js on the Chrome Web Store

8. Link Gopher

What it does: Extracts every link on a page and lists them, with a filter for domains.

How pentesters use it: Quick manual mapping of a site’s links and third-party domains. For a full crawl, use your proxy’s spider instead.

Link Gopher on the Chrome Web Store

Web application testing extensions

9. OWASP Penetration Testing Kit

What it does: An open-source OWASP project that works inside your live, logged-in browser session. It captures the HTTP requests your browsing generates, runs selected dynamic (DAST) checks against them, and analyzes loaded JavaScript and HTML for insecure patterns.

How pentesters use it: Testing authenticated workflows that are awkward to reproduce in a separate scanner. It was updated in September 2026, which makes it one of the most actively maintained tools here.

OWASP Penetration Testing Kit on the Chrome Web Store

10. HackBar

What it does: Adds a HackBar tab to Chrome DevTools. You can load the current request (or paste a cURL command), edit the method, body and headers, add custom payloads and resend it.

How pentesters use it: Fast manual testing of parameters without leaving the browser.

HackBar on the Chrome Web Store

11. Hack-Tools

What it does: A reference toolbox with reverse shell generators, XSS and SQL injection payloads, encoders, hash tools and Linux command snippets.

How pentesters use it: Copying common payloads quickly during a test or CTF. The listing hasn’t been updated since 2023, but it is Manifest V3 and still installs.

Hack-Tools on the Chrome Web Store

12. d3coder

What it does: Encodes and decodes selected text from the right-click menu, including Base64, ROT13 and Unix timestamp conversion. You can customize which conversions appear in the menu.

How pentesters use it: Decoding tokens and parameters you find while testing. For more on how these schemes differ from real encryption, see our guide to {L(“cryptography-tools”,”cryptography tools”)}.

d3coder on the Chrome Web Store

13. Cookie-Editor

What it does: Lets you view, add, edit, delete, import and export cookies for the current site.

How pentesters use it: Testing session handling, cookie flags and authorization checks. It replaces the original EditThisCookie, whose listing is gone. Be careful with lookalikes: removed extensions tend to attract malicious clones, so install from the exact listing.

Cookie-Editor on the Chrome Web Store

14. User-Agent Switcher and Manager

What it does: Changes the browser’s user-agent string, per site if you want.

How pentesters use it: Checking whether a site serves different content, or different security controls, to mobile devices, bots or old browsers.

User-Agent Switcher and Manager on the Chrome Web Store

15. Talend API Tester

What it does: A request builder for HTTP and REST APIs, with support for custom headers, bodies, authentication and saved scenarios.

How pentesters use it: Crafting and replaying requests by hand. It fills the gap left by Request Maker and Tamper Chrome. For interception, route traffic through Burp Suite or ZAP.

Talend API Tester on the Chrome Web Store

Proxy and workflow extensions

16. FoxyProxy

What it does: Switches Chrome between proxy profiles, with URL pattern rules.

How pentesters use it: The standard way to send browser traffic to Burp Suite or OWASP ZAP with one click, and to send only in-scope domains through the proxy.

FoxyProxy on the Chrome Web Store

17. Proxy SwitchyOmega 3 (ZeroOmega)

What it does: A Manifest V3 fork of the popular SwitchyOmega proxy manager, with auto-switch rules and PAC script support.

How pentesters use it: Managing several upstream proxies with rules. It’s a direct replacement if you relied on the original SwitchyOmega or SwitchySharp.

Proxy SwitchyOmega 3 (ZeroOmega) on the Chrome Web Store

18. Clear Cache

What it does: Clears the cache, and optionally cookies and other site data, with one click.

How pentesters use it: Retesting a page without stale cached responses. It replaces Classic Cache Killer.

Clear Cache on the Chrome Web Store

19. Web Developer

What it does: Adds a toolbar for inspecting and changing pages: show hidden form fields, disable JavaScript, view cookies, outline elements and more.

How pentesters use it: Revealing hidden inputs and client-side restrictions you can then test against the server.

Web Developer on the Chrome Web Store

20. Note Anywhere

What it does: Pins sticky notes to specific web pages and brings them back when you return.

How pentesters use it: Keeping findings and reminders attached to the exact pages you’re testing. Don’t store client secrets in it.

Note Anywhere on the Chrome Web Store

How to install security extensions safely

Extensions run with broad access to the pages you visit, so a compromised one can steal session cookies and passwords. In December 2024, attackers phished the developer of Cyberhaven’s Chrome extension and pushed a malicious update to it and dozens of other extensions (BleepingComputer). A few habits reduce the risk:

For desktop tools that go beyond the browser, such as Burp Suite, Nmap and Wireshark, see our roundup of cybersecurity tools. If you’re building these skills for a job, our guide on moving into a cybersecurity career covers where to start.

For a short weekday roundup of new vulnerabilities, breaches and tools, sign up for the CyberExperts Daily Brief.

Frequently asked questions

Are Chrome hacking extensions legal?

Installing them is legal. Using them against a website or system without the owner’s permission usually isn’t. Only test systems you own or have written authorization to test, such as a bug bounty program’s in-scope targets.

Why did so many hacking extensions disappear from the Chrome Web Store?

Some were abandoned by their developers or removed by Google. Chrome also disabled all Manifest V2 extensions in July 2025, and Google removed the remaining Manifest V2 items from the Web Store on August 31, 2026. Tools that were never updated to Manifest V3 no longer work.

Can a Chrome extension replace Burp Suite or OWASP ZAP?

No. Extensions are good for recon, quick edits and encoding. For intercepting and modifying traffic, scanning and repeating requests at scale, use a proxy such as Burp Suite or ZAP, and use FoxyProxy to route Chrome’s traffic to it.

What happened to EditThisCookie and Tamper Chrome?

Both original listings return the Chrome Web Store’s unavailable page. Cookie-Editor is a maintained alternative for cookies. For request tampering, use Burp Suite or ZAP, or Talend API Tester to build requests by hand.

Is it safe to install hacking extensions in my main browser?

It’s better not to. Use a separate Chrome profile for testing, install only from verified listings, and limit each extension’s site access. A compromised extension can read your session cookies on every site it has access to.

Which Chrome extension is best for beginners?

Start with Wappalyzer for recon, Cookie-Editor for session testing and the OWASP Penetration Testing Kit for basic web checks. Practice on intentionally vulnerable apps such as OWASP Juice Shop rather than real websites.

Sources

Stay Current

Newer CyberExperts coverage on this topic

This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.

Latest Daily Brief

Friday’s brief: forgotten servers on a seven-country advisory, then Splunk, Bricksforge and exposed dashboards

The fastest way to catch up on what changed after this article was published.

Read Today's Brief

George Mutune

I am a cyber security professional with a passion for delivering proactive strategies for day to day operational challenges. I am excited to be working with leading cyber security teams and professionals on projects that involve machine learning & AI solutions to solve the cyberspace menace and cut through inefficiency that plague today's business environments.