4 items
ParamHound — hidden HTTP parameter discovery extension for authorized security testing (Manifest V3). ParamHound finds hidden HTTP request parameters and headers for web security testing. HOW IT WORKS - Capture a request (the page URL and its API calls), or type one in manually. - Active fuzzing: it batches thousands of known parameter names into requests and bisects the ones that change the response, then confirms each with repeat requests against a multi-sample baseline to filter out response noise. - Page + JavaScript analysis: it also reads the page and its same-origin scripts and lists the parameter names the site actually references — real leads, not guesses. - Detection signals: value reflection, status/redirect changes, new JSON keys, and structural changes, calibrated per target so dynamic pages don't false-positive. - Rate-limit aware: HTTP 429/503 responses are recognised as rate limiting, backed off, and never mistaken for a parameter effect. FEATURES - Query, form-body, JSON-body, and header injection points - Fast batched scanning with bisection, or a thorough one-request-per-parameter mode - Aggressive / Balanced / Strict sensitivity - Per-tab results, live diagnostics, and JSON / CSV / Markdown export - Bundled wordlists (~6,400 parameters, ~1,200 headers) plus your own imports - Rate limiting, per-job request caps, and scope controls PRIVACY Everything runs locally in your browser. ParamHound sends requests only to the target you choose to test, using your existing session. It has no servers, no analytics, and transmits no data anywhere.
Jul 28, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.