Autonomous Fresh Bug Bounty & VDP Discovery Radar
Discovers newly launched, self-hosted, and unlisted bug bounty programs in the background without needing to visit websites.
Left (v1.2 Showcase): In-app auto-update notifications, Active Tab Target Sniffer (detects current browsing targets), โญ Bookmarks, ๐ Private Recon Notes, and multi-tool exports.
Right: Cyberpunk Bento Grid with 5 reactive metric cards (13,757+ Programs, 39,642+ Targets, 852+ Fresh, 1,586+ Self-Hosted, 224+ Private), global regional radar, and 1-click scope copy.
Traditional browser extensions require you to manually browse to target websites before they detect anything. BountyRadar inverts this model:
- Autonomous Feed Ingestion: In the background, BountyRadar pulls from live global trackers: Disclose.io (diodb), HackerOne, Bugcrowd, ProjectDiscovery, Intigriti, YesWeHack, plus 3,500+ in-scope Wildcards and 36,000+ Target Domains.
- Massive Index of 12,500+ Organizations & 30,000+ Targets: Dynamically aggregates over 12,500+ verified bug bounty & VDP organizations and 30,000+ in-scope target domains across 20+ countries and sovereign extensions.
- ๐ฏ Dedicated Wildcard Scope Radar: Filter directly by wildcard targets (
*.example.com) across 1,800+ programs for deep subdomain takeover & enumeration workflows. - ๐ Global Country & TLD Regional Radar: Automatically detects and tags programs by national domain extensions and sovereign regions (
๐๏ธ .gov,๐ฉ๐ช .de,๐ฌ๐ง .uk,๐ณ๐ฑ .nl,๐จ๐ญ .ch,๐ฎ๐ณ .in,๐ฆ๐บ .au,๐จ๐ฆ .ca,๐ซ๐ท .fr,๐ช๐บ .eu,๐ .edu,๐ง๐ท .br,๐ US/Global). - Zero-Click Auto-Sync: Automatically checks and syncs live feeds on browser startup and popup launchโno manual buttons required.
- Diff & Fresh Discovery Engine: Tracks newly added programs and flags them with
๐ฅ NEW. - 1-Click Scope Copy: Copy all in-scope domains formatted line-by-line, ready to pipe into
subfinder,httpx, ornuclei.
BountyRadar works identically on Windows, Linux, and macOS across any Chromium or Firefox-based browser.
git clone https://github.com/tejassroot/BountyRadar.git- Click the green Code button at the top of this repository.
- Click Download ZIP.
- Extract the downloaded
BountyRadar-main.zipfolder on your computer.
Recommended: Stays permanently installed across all browser sessions.
- Open your browser and navigate to the extensions page:
- Chrome:
chrome://extensions - Brave:
brave://extensions - Edge:
edge://extensions
- Chrome:
- Toggle on Developer mode (switch in the top-right corner).
- Click the "Load unpacked" button in the top-left corner.
- Select the extracted
BountyRadarfolder (containingmanifest.json). - Done! Click the puzzle icon (๐งฉ) on your browser toolbar and pin BountyRadar.
- Open Firefox and type in the address bar:
about:debugging#/runtime/this-firefox - Click "Load Temporary Add-onโฆ".
- Open the
BountyRadarfolder and select themanifest.jsonfile. - Pin the icon to your toolbar from the Extensions (๐งฉ) menu.
Or run from terminal with live reload:
# Linux / macOS
cd BountyRadar && npx web-ext run
# Windows (PowerShell / Command Prompt)
cd BountyRadar; npx web-ext run| Feature | Description |
|---|---|
| ๐ RFC 9116 security.txt Sniffer | Passively detects hidden & unlisted VDPs on any domain you browse (/.well-known/security.txt) with PGP keys, direct contacts, and 1-click bookmarks. |
| ๐ In-App Auto-Updates | Checks GitHub releases in the background and alerts researchers with 1-click update downloads. |
| Instant push webhook alerts to your Telegram bot or email digest when fresh bug bounty programs drop. | |
| ๐ฏ Active Tab Target Sniffer | Instantly highlights when you browse an in-scope website (๐ฐ $15,000 / ๐ฏ In-Scope / ๐ VDP). |
| ๐งฐ Multi-Tool Exporter | 1-Click exports for Nuclei (targets.txt), Burp Suite Scope (burp_scope.json), and Subfinder. |
| โญ Bookmarks & ๐ Notes | Star favorite programs and write private confidential recon notes directly onto target cards. |
| โก Zero-Click Sync | Automatically pulls fresh data on startup; no manual sync clicking needed. |
| ๐ฏ Wildcard Radar | Isolate 1,800+ wildcard domain programs (*.example.com) for massive subdomain expansion. |
| ๐ Country & TLD Radar | Filter across 20+ national and sovereign domains (.gov, .de, .uk, .nl, .in, .ch, .au, .ca, .fr, etc.). |
| โพ๏ธ Unlimited Live Ingestion | Ingests 13,750+ programs and 39,600+ targets dynamically with cache-busting live diffs. |
| ๐ 5-Card Bento Grid | Real-time counts for Programs, ๐ฏ Targets, ๐ฅ Fresh, ๐ Self-Hosted, and ๐ Private. |
| ๐ 1-Click Scope Copy | Click "Copy Scope" on any program to copy all target domains formatted for recon CLI tools. |
| ๐ท๏ธ Asset Category Chips | Filter across Web, API, Mobile, Cloud, Crypto, Hardware/IoT, and security.txt. |
| ๐ Smart Search & Hotkey | Press / to focus search across 30,000+ target domains, companies, countries, and platforms. |
BountyRadar autonomously monitors global trackers in the background. When fresh bug bounty programs, unlisted self-hosted VDPs, or escalated scopes are detected, it immediately pushes structured alerts straight to your phone or desktop.
๐จ BountyRadar Discovery Alert
Found 3 newly discovered bug bounty programs!
1. Acme Cloud Security
โข Type: ๐ฐ Bounty | ๐ข HackerOne
โข Policy: https://hackerone.com/acme
โข In-Scope: *.acmecloud.com, api.acme.io
2. Fintech Secure Ltd
โข Type: ๐ฏ VDP | ๐ Self-Hosted
โข Policy: https://fintech.de/.well-known/security.txt
โข In-Scope: *.fintech.de, auth.fintech.de
- Create Bot: Message @BotFather on Telegram and send
/newbot. Follow prompts and copy the HTTP API Token. - Activate: Open your new bot's link (e.g.,
t.me/your_bounty_bot) and press Start (or send/start). - Get Chat ID: Message @userinfobot on Telegram to get your numeric user
Id. - Configure: Open BountyRadar, click the โ๏ธ (Settings) icon in the header, toggle Telegram Push Alerts, paste your token and Chat ID, and click "Ping Telegram Test".
- Create a free account at resend.com (includes 3,000 free emails/month) and generate an API key.
- Open BountyRadar Settings (โ๏ธ), toggle Email Digest Alerts, enter your Resend API Key and Destination Email, then click "Send Test Email".
BountyRadar/
โโโ manifest.json # Manifest V3 cross-browser configuration
โโโ background.js # Background service worker & auto-sync alarms
โโโ feeds.js # Multi-source parser (Disclose.io, H1, Bugcrowd, etc.)
โโโ popup.html # Cyber-obsidian bento grid dashboard
โโโ popup.css # Glassmorphic responsive dark stylesheet
โโโ popup.js # Reactive state, token search & clipboard integration
โโโ icons/ # Extension brand assets (16px, 48px, 128px)
โโโ assets/images/ # Interface preview screenshots and hero banner
โโโ dist/ # Packaged production zip release
Contributions, feedback, and feed additions are welcome! Open an issue or pull request.
Licensed under the MIT License.


