Updated September 2026. We rechecked every extension on this list against the Chrome Web Store in September 2026. Eight of the Web Store links in the original 2020 article now lead to unavailable listings, one more tool is a Manifest V2 package that current Chrome won’t run, and several others had no working listing at all. We removed them and added maintained alternatives, so the list now has 20 working extensions.
Browser extensions won’t replace a full testing proxy such as Burp Suite or OWASP ZAP. They do make everyday recon and web testing faster: fingerprinting a site’s technology, editing cookies and headers, switching proxies, encoding payloads and pulling links from a page. Everything below is free to install, and each one was live in the Chrome Web Store and built on Manifest V3 when we checked.
Use these only on systems you own or have written permission to test. Running attack payloads against other people’s sites is illegal in most countries, even if the tool is free and easy to install.
Know what matters before your first meeting.
Weekday mornings. Five minutes. What changed in security, why it matters.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What changed since the original list
Two things forced a rewrite.
- Manifest V2 is gone. Google disabled Manifest V2 extensions for all Chrome users with Chrome 138 in July 2025, and on August 31, 2026 it removed the remaining Manifest V2 extensions from the Chrome Web Store (Chrome for Developers). Older tools that were never updated simply stop working.
- Many listings disappeared. When we checked each link from the old article, these items returned the Web Store’s “unavailable” page: Tamper Chrome, Proxy SwitchySharp, Proxy SwitchyOmega (the original), Bishop Vulnerability Scan, Site Spider Mark II, Classic Cache Killer, Request Maker and EditThisCookie (the original listing). Open Port Check Tool is still a Manifest V2 package, which current Chrome won’t run.
We also dropped entries we couldn’t match to a live Web Store listing (Form Fuzzer, XSS Rays, WebSecurify, Port Scanner and iMacros), plus XSS ChEF, which was a proof-of-concept exploitation framework rather than a store extension. The old article also described Tamper Data, which was a Firefox add-on, and linked it to the retired Tamper Chrome listing.
The 20 best Chrome extensions for ethical hacking at a glance
| Extension | Best for | Replaces (from the old list) |
|---|---|---|
| Wappalyzer | Technology fingerprinting | Kept |
| BuiltWith Technology Profiler | Technology fingerprinting | New |
| Shodan | Exposed ports and services | Open Port Check Tool, Port Scanner |
| IP Address and Domain Information | DNS, ASN and hosting recon | Kept |
| Wayback Machine | Old pages and forgotten endpoints | New |
| DotGit | Exposed .git and config files | Bishop Vulnerability Scan |
| Retire.js | Vulnerable JavaScript libraries | New |
| Link Gopher | Extracting links from a page | Site Spider Mark II |
| OWASP Penetration Testing Kit | All-in-one web testing | Kept |
| HackBar | Manual payload testing | Kept |
| Hack-Tools | Payload and shell cheat sheets | XSS Rays, Form Fuzzer |
| d3coder | Encoding and hashing | Kept |
| Cookie-Editor | Viewing and editing cookies | EditThisCookie |
| User-Agent Switcher and Manager | Testing device-specific behavior | New |
| Talend API Tester | Crafting HTTP and API requests | Request Maker, Tamper Chrome |
| FoxyProxy | Routing traffic to Burp or ZAP | Proxy SwitchySharp |
| Proxy SwitchyOmega 3 (ZeroOmega) | Rule-based proxy switching | Proxy SwitchyOmega |
| Clear Cache | One-click cache clearing | Classic Cache Killer |
| Web Developer | Forms, cookies and page inspection | New |
| Note Anywhere | Notes on the page you’re testing | Kept |
Reconnaissance and fingerprinting extensions
Recon, sometimes called information gathering or banner grabbing, tells you what a site runs so you can look up known vulnerabilities for those versions.
1. Wappalyzer
What it does: Identifies the content management system, web server, JavaScript frameworks, analytics tools, CDN and other technologies a site uses, often with version numbers.
How pentesters use it: A quick first look at a target. Version numbers point you to the CVEs worth checking. It was the most widely used extension on this list when we checked, with about 3 million users.
Wappalyzer on the Chrome Web Store
2. BuiltWith Technology Profiler
What it does: Another technology profiler that pulls from BuiltWith’s database, including hosting, email and advertising providers.
How pentesters use it: A second opinion when Wappalyzer misses something, especially third-party services. Its listing was last updated in 2022, but it is a Manifest V3 package and still installs.
BuiltWith Technology Profiler on the Chrome Web Store
3. Shodan
What it does: Shodan’s official extension. It shows where the current site is hosted, who owns the IP address and which other ports and services Shodan’s internet-wide scans have seen on it.
How pentesters use it: Passive port and service discovery without sending a single packet to the target yourself. It replaces the old port-scanner extensions, which are no longer available.
Shodan on the Chrome Web Store
4. IP Address and Domain Information
What it does: Shows DNS records, IP geolocation, hosting provider, ASN and routing details for the site you’re on.
How pentesters use it: Mapping who hosts a target and which other domains share its infrastructure.
IP Address and Domain Information on the Chrome Web Store
5. Wayback Machine
What it does: The Internet Archive’s official extension. It shows archived copies of the page you’re viewing.
How pentesters use it: Finding old pages, parameters and endpoints that have vanished from the live site but may still work on the server.
Wayback Machine on the Chrome Web Store
6. DotGit
What it does: Checks each site you visit for exposed .git, .svn and .hg folders, plus .env and .DS_Store files, and notifies you when it finds one.
How pentesters use it: Catching a common and serious misconfiguration: an exposed Git folder can leak source code, credentials and API keys. It covers the main job the retired Bishop Vulnerability Scan used to do.
DotGit on the Chrome Web Store
7. Retire.js
What it does: Scans pages for JavaScript libraries with known vulnerabilities, such as old versions of jQuery or AngularJS, using the Retire.js database.
How pentesters use it: Flagging outdated front-end libraries, a finding that appears in almost every web app test. The listing is published by the Retire.js project’s author.
Retire.js on the Chrome Web Store
8. Link Gopher
What it does: Extracts every link on a page and lists them, with a filter for domains.
How pentesters use it: Quick manual mapping of a site’s links and third-party domains. For a full crawl, use your proxy’s spider instead.
Link Gopher on the Chrome Web Store
Web application testing extensions
9. OWASP Penetration Testing Kit
What it does: An open-source OWASP project that works inside your live, logged-in browser session. It captures the HTTP requests your browsing generates, runs selected dynamic (DAST) checks against them, and analyzes loaded JavaScript and HTML for insecure patterns.
How pentesters use it: Testing authenticated workflows that are awkward to reproduce in a separate scanner. It was updated in September 2026, which makes it one of the most actively maintained tools here.
OWASP Penetration Testing Kit on the Chrome Web Store
10. HackBar
What it does: Adds a HackBar tab to Chrome DevTools. You can load the current request (or paste a cURL command), edit the method, body and headers, add custom payloads and resend it.
How pentesters use it: Fast manual testing of parameters without leaving the browser.
HackBar on the Chrome Web Store
11. Hack-Tools
What it does: A reference toolbox with reverse shell generators, XSS and SQL injection payloads, encoders, hash tools and Linux command snippets.
How pentesters use it: Copying common payloads quickly during a test or CTF. The listing hasn’t been updated since 2023, but it is Manifest V3 and still installs.
Hack-Tools on the Chrome Web Store
12. d3coder
What it does: Encodes and decodes selected text from the right-click menu, including Base64, ROT13 and Unix timestamp conversion. You can customize which conversions appear in the menu.
How pentesters use it: Decoding tokens and parameters you find while testing. For more on how these schemes differ from real encryption, see our guide to {L(“cryptography-tools”,”cryptography tools”)}.
d3coder on the Chrome Web Store
13. Cookie-Editor
What it does: Lets you view, add, edit, delete, import and export cookies for the current site.
How pentesters use it: Testing session handling, cookie flags and authorization checks. It replaces the original EditThisCookie, whose listing is gone. Be careful with lookalikes: removed extensions tend to attract malicious clones, so install from the exact listing.
Cookie-Editor on the Chrome Web Store
14. User-Agent Switcher and Manager
What it does: Changes the browser’s user-agent string, per site if you want.
Know what matters before your first meeting.
Weekday mornings. Five minutes. What changed in security, why it matters.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
How pentesters use it: Checking whether a site serves different content, or different security controls, to mobile devices, bots or old browsers.
User-Agent Switcher and Manager on the Chrome Web Store
15. Talend API Tester
What it does: A request builder for HTTP and REST APIs, with support for custom headers, bodies, authentication and saved scenarios.
How pentesters use it: Crafting and replaying requests by hand. It fills the gap left by Request Maker and Tamper Chrome. For interception, route traffic through Burp Suite or ZAP.
Talend API Tester on the Chrome Web Store
Proxy and workflow extensions
16. FoxyProxy
What it does: Switches Chrome between proxy profiles, with URL pattern rules.
How pentesters use it: The standard way to send browser traffic to Burp Suite or OWASP ZAP with one click, and to send only in-scope domains through the proxy.
FoxyProxy on the Chrome Web Store
17. Proxy SwitchyOmega 3 (ZeroOmega)
What it does: A Manifest V3 fork of the popular SwitchyOmega proxy manager, with auto-switch rules and PAC script support.
How pentesters use it: Managing several upstream proxies with rules. It’s a direct replacement if you relied on the original SwitchyOmega or SwitchySharp.
Proxy SwitchyOmega 3 (ZeroOmega) on the Chrome Web Store
18. Clear Cache
What it does: Clears the cache, and optionally cookies and other site data, with one click.
How pentesters use it: Retesting a page without stale cached responses. It replaces Classic Cache Killer.
Clear Cache on the Chrome Web Store
19. Web Developer
What it does: Adds a toolbar for inspecting and changing pages: show hidden form fields, disable JavaScript, view cookies, outline elements and more.
How pentesters use it: Revealing hidden inputs and client-side restrictions you can then test against the server.
Web Developer on the Chrome Web Store
20. Note Anywhere
What it does: Pins sticky notes to specific web pages and brings them back when you return.
How pentesters use it: Keeping findings and reminders attached to the exact pages you’re testing. Don’t store client secrets in it.
Note Anywhere on the Chrome Web Store
How to install security extensions safely
Extensions run with broad access to the pages you visit, so a compromised one can steal session cookies and passwords. In December 2024, attackers phished the developer of Cyberhaven’s Chrome extension and pushed a malicious update to it and dozens of other extensions (BleepingComputer). A few habits reduce the risk:
- Use a separate Chrome profile for testing. Keep pentest extensions out of the profile you use for email, banking and admin consoles.
- Install from the exact listing. Check the publisher, user count and last-updated date. Be suspicious of new listings that copy the name of a removed tool.
- Limit site access. In
chrome://extensions, set an extension’s site access to “On click” or specific sites when you can. - Remove what you don’t use. Fewer extensions means a smaller attack surface.
- Keep Chrome updated so extensions get Chrome’s latest security fixes and policy checks.
For desktop tools that go beyond the browser, such as Burp Suite, Nmap and Wireshark, see our roundup of cybersecurity tools. If you’re building these skills for a job, our guide on moving into a cybersecurity career covers where to start.
For a short weekday roundup of new vulnerabilities, breaches and tools, sign up for the CyberExperts Daily Brief.
Frequently asked questions
Are Chrome hacking extensions legal?
Installing them is legal. Using them against a website or system without the owner’s permission usually isn’t. Only test systems you own or have written authorization to test, such as a bug bounty program’s in-scope targets.
Why did so many hacking extensions disappear from the Chrome Web Store?
Some were abandoned by their developers or removed by Google. Chrome also disabled all Manifest V2 extensions in July 2025, and Google removed the remaining Manifest V2 items from the Web Store on August 31, 2026. Tools that were never updated to Manifest V3 no longer work.
Can a Chrome extension replace Burp Suite or OWASP ZAP?
No. Extensions are good for recon, quick edits and encoding. For intercepting and modifying traffic, scanning and repeating requests at scale, use a proxy such as Burp Suite or ZAP, and use FoxyProxy to route Chrome’s traffic to it.
What happened to EditThisCookie and Tamper Chrome?
Both original listings return the Chrome Web Store’s unavailable page. Cookie-Editor is a maintained alternative for cookies. For request tampering, use Burp Suite or ZAP, or Talend API Tester to build requests by hand.
Is it safe to install hacking extensions in my main browser?
It’s better not to. Use a separate Chrome profile for testing, install only from verified listings, and limit each extension’s site access. A compromised extension can read your session cookies on every site it has access to.
Which Chrome extension is best for beginners?
Start with Wappalyzer for recon, Cookie-Editor for session testing and the OWASP Penetration Testing Kit for basic web checks. Practice on intentionally vulnerable apps such as OWASP Juice Shop rather than real websites.
Sources
- Chrome for Developers, Manifest V2 support timeline: developer.chrome.com
- Chrome Web Store listings for each extension, checked September 25, 2026 (linked in each entry above)
- Chrome Web Store Help, Install and manage extensions: support.google.com
- BleepingComputer, New details reveal how hackers hijacked 35 Google Chrome extensions: bleepingcomputer.com
- OWASP Penetration Testing Kit project: owasp.org
- Retire.js project: retirejs.github.io
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Why Just Checking the Box on Risk Assessment Isn’t Enough
Compliance-driven risk assessments can pass an audit and still miss real exposure. Here’s why physical and cyber reviews must work together, why...
Cheapest Cybersecurity Certifications in 2026 (Verified Prices)
The cheapest cybersecurity certifications in 2026, with U.S. prices checked October 8, 2026, renewal and annual fees, three-year costs and which to...
6 Solutions for Setting AI Agent Guardrails at Scale
Agents don't just answer questions—they take actions. Compare six platforms that set guardrails on identity, intent, tools, and consequence at runtime.
Friday’s brief: forgotten servers on a seven-country advisory, then Splunk, Bricksforge and exposed dashboards
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.