1 item
Automatically generates a CSRF PoC HTML file for the current page. CSRF PoC Generator helps security professionals and penetration testers quickly build Cross-Site Request Forgery (CSRF) proof-of-concept exploits from any HTML form on a page, no manual HTML writing required. HOW IT WORKS 1. Navigate to a page containing the form you want to test. 2. Click the extension icon and select "Scan Page for Forms" (you'll get a picker if the page has multiple forms). 3. Review the scraped fields in an editable list — every field type (text, checkbox, radio, dropdown, multi-select) is rendered as its real control and mirrors actual browser submission rules: unchecked boxes and unselected radios are left out, disabled fields are never scraped. 4. Optionally click "Fill All (Fake Data)" to auto-fill blank fields with realistic sample values. Anti-CSRF-token-shaped fields (csrf, xsrf, nonce, authenticity, etc.) are always left untouched so the PoC stays valid against apps that check them. 5. Click "Generate PoC" to produce a self-contained HTML exploit page, with an optional auto-submit script for one-click testing. 6. Copy the PoC to your clipboard or download it as an .html file. KEY FEATURES • One-click form scanning with multi-form picker • Full editable field review before generating the PoC • Smart fake-data filler that skips anti-CSRF tokens • Faithful handling of checkboxes, radio groups, and single/multi-select dropdowns • Optional auto-submit for immediate PoC testing • Copy-to-clipboard or download-as-HTML output • Clean UI with dark mode support PRIVACY & PERMISSIONS This extension collects no data and makes no network requests of its own. It only reads form fields from the tab you are actively viewing, and only after you click "Scan Page for Forms." The generated PoC file stays on your device unless you choose to share it. SECURITY NOTICE This tool is intended for legitimate, authorized security testing only. Always obtain proper authorization before testing any web application for CSRF vulnerabilities. The author is not responsible for misuse of this tool.
Sep 14, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.