mr-r0ot/JSmap-Scanner

GitHub: mr-r0ot/JSmap-Scanner

Stars: 1 | Forks: 0

# ![JSmap Logo](https://static.pigsec.cn/wp-content/uploads/repos/2026/06/96dfa0d849231306.png) # JSmap - The Ultimate Recon & XSS Toolkit Welcome to **JSmap**, the black‑hat hacker’s dream CLI scanner. Designed to be lightning‑fast, deeply intelligent, and outrageously configurable, JSmap will make you feel like a wizard on your first pentest. ## 🛠 Some test ![JSmap one](https://static.pigsec.cn/wp-content/uploads/repos/2026/06/c2ed3549e2231308.png) ![JSmap 3](https://static.pigsec.cn/wp-content/uploads/repos/2026/06/0ef1a0831a231309.png) ## 🚀 What Is JSmap? JSmap is a next‑generation reconnaissance and vulnerability‑discovery toolkit that: 1. **Crawls** entire web domains in parallel. 2. **Extracts** XSS‑prone URL patterns (summarized!). 3. **Detects** every JavaScript library/framework, version, and path. 4. **Scans** found JS files with **retirejs** for known CVEs. 5. **Automates** post‑scan XSStrike attacks for deep XSS analysis. You don’t need to be a seasoned hacker—JSmap guides you from zero to hero. ## 🔥 Features at a Glance * **High‑Speed Crawl**: Fully concurrent with customizable thread pool. * **Live Progress Bar**: See exactly what page you’re on and how many remain. * **Summarized XSS Patterns**: Instead of hundreds of `?p=78, ?p=80…`, JSmap reports only `?p=`—max efficiency. * **JS Asset Discovery**: Finds every `