Skip to content

Latest commit

ย 

History

19 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

BountyRadar ๐Ÿ“ก

Autonomous Fresh Bug Bounty & VDP Discovery Radar
Discovers newly launched, self-hosted, and unlisted bug bounty programs in the background without needing to visit websites.

GitHub license Manifest V3 Supported Browsers

BountyRadar Hero Banner


๐Ÿ“ธ Interface & Live Radar Preview

BountyRadar v1.2 Auto-Update & Active Scope Sniffer ย ย ย ย  BountyRadar Ultra-Pro Cyberpunk Bento UI

Left (v1.2 Showcase): In-app auto-update notifications, Active Tab Target Sniffer (detects current browsing targets), โญ Bookmarks, ๐Ÿ“ Private Recon Notes, and multi-tool exports.
Right: Cyberpunk Bento Grid with 5 reactive metric cards (13,757+ Programs, 39,642+ Targets, 852+ Fresh, 1,586+ Self-Hosted, 224+ Private), global regional radar, and 1-click scope copy.


โšก How It Works (Without Visiting Sites)

Traditional browser extensions require you to manually browse to target websites before they detect anything. BountyRadar inverts this model:

  1. Autonomous Feed Ingestion: In the background, BountyRadar pulls from live global trackers: Disclose.io (diodb), HackerOne, Bugcrowd, ProjectDiscovery, Intigriti, YesWeHack, plus 3,500+ in-scope Wildcards and 36,000+ Target Domains.
  2. Massive Index of 12,500+ Organizations & 30,000+ Targets: Dynamically aggregates over 12,500+ verified bug bounty & VDP organizations and 30,000+ in-scope target domains across 20+ countries and sovereign extensions.
  3. ๐ŸŽฏ Dedicated Wildcard Scope Radar: Filter directly by wildcard targets (*.example.com) across 1,800+ programs for deep subdomain takeover & enumeration workflows.
  4. ๐ŸŒ Global Country & TLD Regional Radar: Automatically detects and tags programs by national domain extensions and sovereign regions (๐Ÿ›๏ธ .gov, ๐Ÿ‡ฉ๐Ÿ‡ช .de, ๐Ÿ‡ฌ๐Ÿ‡ง .uk, ๐Ÿ‡ณ๐Ÿ‡ฑ .nl, ๐Ÿ‡จ๐Ÿ‡ญ .ch, ๐Ÿ‡ฎ๐Ÿ‡ณ .in, ๐Ÿ‡ฆ๐Ÿ‡บ .au, ๐Ÿ‡จ๐Ÿ‡ฆ .ca, ๐Ÿ‡ซ๐Ÿ‡ท .fr, ๐Ÿ‡ช๐Ÿ‡บ .eu, ๐ŸŽ“ .edu, ๐Ÿ‡ง๐Ÿ‡ท .br, ๐ŸŒ US/Global).
  5. Zero-Click Auto-Sync: Automatically checks and syncs live feeds on browser startup and popup launchโ€”no manual buttons required.
  6. Diff & Fresh Discovery Engine: Tracks newly added programs and flags them with ๐Ÿ”ฅ NEW.
  7. 1-Click Scope Copy: Copy all in-scope domains formatted line-by-line, ready to pipe into subfinder, httpx, or nuclei.

๐Ÿš€ Installation Guide

BountyRadar works identically on Windows, Linux, and macOS across any Chromium or Firefox-based browser.

Step 1: Download the Repository

Option A: Via Git (Windows / Linux / macOS)

git clone https://github.com/tejassroot/BountyRadar.git

Option B: Download as ZIP (No Git Required)

  1. Click the green Code button at the top of this repository.
  2. Click Download ZIP.
  3. Extract the downloaded BountyRadar-main.zip folder on your computer.

Step 2: Load into Your Browser

๐ŸŒ Google Chrome, Brave, Microsoft Edge, Opera (Windows & Linux)

Recommended: Stays permanently installed across all browser sessions.

  1. Open your browser and navigate to the extensions page:
    • Chrome: chrome://extensions
    • Brave: brave://extensions
    • Edge: edge://extensions
  2. Toggle on Developer mode (switch in the top-right corner).
  3. Click the "Load unpacked" button in the top-left corner.
  4. Select the extracted BountyRadar folder (containing manifest.json).
  5. Done! Click the puzzle icon (๐Ÿงฉ) on your browser toolbar and pin BountyRadar.

๐ŸฆŠ Mozilla Firefox (Windows & Linux)

  1. Open Firefox and type in the address bar:
    about:debugging#/runtime/this-firefox
    
  2. Click "Load Temporary Add-onโ€ฆ".
  3. Open the BountyRadar folder and select the manifest.json file.
  4. Pin the icon to your toolbar from the Extensions (๐Ÿงฉ) menu.

Or run from terminal with live reload:

# Linux / macOS
cd BountyRadar && npx web-ext run

# Windows (PowerShell / Command Prompt)
cd BountyRadar; npx web-ext run

๐ŸŽฏ Features & Usage

Feature Description
๐Ÿ“œ RFC 9116 security.txt Sniffer Passively detects hidden & unlisted VDPs on any domain you browse (/.well-known/security.txt) with PGP keys, direct contacts, and 1-click bookmarks.
๐Ÿš€ In-App Auto-Updates Checks GitHub releases in the background and alerts researchers with 1-click update downloads.
โœˆ๏ธ Telegram & โœ‰๏ธ Email Alerts Instant push webhook alerts to your Telegram bot or email digest when fresh bug bounty programs drop.
๐ŸŽฏ Active Tab Target Sniffer Instantly highlights when you browse an in-scope website (๐Ÿ’ฐ $15,000 / ๐ŸŽฏ In-Scope / ๐Ÿ“œ VDP).
๐Ÿงฐ Multi-Tool Exporter 1-Click exports for Nuclei (targets.txt), Burp Suite Scope (burp_scope.json), and Subfinder.
โญ Bookmarks & ๐Ÿ“ Notes Star favorite programs and write private confidential recon notes directly onto target cards.
โšก Zero-Click Sync Automatically pulls fresh data on startup; no manual sync clicking needed.
๐ŸŽฏ Wildcard Radar Isolate 1,800+ wildcard domain programs (*.example.com) for massive subdomain expansion.
๐ŸŒ Country & TLD Radar Filter across 20+ national and sovereign domains (.gov, .de, .uk, .nl, .in, .ch, .au, .ca, .fr, etc.).
โ™พ๏ธ Unlimited Live Ingestion Ingests 13,750+ programs and 39,600+ targets dynamically with cache-busting live diffs.
๐Ÿ“Š 5-Card Bento Grid Real-time counts for Programs, ๐ŸŽฏ Targets, ๐Ÿ”ฅ Fresh, ๐ŸŒ Self-Hosted, and ๐Ÿ”’ Private.
๐Ÿ“‹ 1-Click Scope Copy Click "Copy Scope" on any program to copy all target domains formatted for recon CLI tools.
๐Ÿท๏ธ Asset Category Chips Filter across Web, API, Mobile, Cloud, Crypto, Hardware/IoT, and security.txt.
๐Ÿ” Smart Search & Hotkey Press / to focus search across 30,000+ target domains, companies, countries, and platforms.

โœˆ๏ธ Real-Time Telegram & Email Alert Webhooks

BountyRadar autonomously monitors global trackers in the background. When fresh bug bounty programs, unlisted self-hosted VDPs, or escalated scopes are detected, it immediately pushes structured alerts straight to your phone or desktop.

๐Ÿ“ฑ Live Preview: What Your Alert Looks Like

๐Ÿšจ BountyRadar Discovery Alert
Found 3 newly discovered bug bounty programs!

1. Acme Cloud Security
โ€ข Type: ๐Ÿ’ฐ Bounty | ๐Ÿข HackerOne
โ€ข Policy: https://hackerone.com/acme
โ€ข In-Scope: *.acmecloud.com, api.acme.io

2. Fintech Secure Ltd
โ€ข Type: ๐ŸŽฏ VDP | ๐ŸŒ Self-Hosted
โ€ข Policy: https://fintech.de/.well-known/security.txt
โ€ข In-Scope: *.fintech.de, auth.fintech.de

โš™๏ธ Setup Instructions

1. Telegram Bot Alerts (Zero Infrastructure, Free)

  1. Create Bot: Message @BotFather on Telegram and send /newbot. Follow prompts and copy the HTTP API Token.
  2. Activate: Open your new bot's link (e.g., t.me/your_bounty_bot) and press Start (or send /start).
  3. Get Chat ID: Message @userinfobot on Telegram to get your numeric user Id.
  4. Configure: Open BountyRadar, click the โš™๏ธ (Settings) icon in the header, toggle Telegram Push Alerts, paste your token and Chat ID, and click "Ping Telegram Test".

2. Email Digest Alerts (via Resend API)

  1. Create a free account at resend.com (includes 3,000 free emails/month) and generate an API key.
  2. Open BountyRadar Settings (โš™๏ธ), toggle Email Digest Alerts, enter your Resend API Key and Destination Email, then click "Send Test Email".

๐Ÿ› ๏ธ Tech Stack & Structure

BountyRadar/
โ”œโ”€โ”€ manifest.json       # Manifest V3 cross-browser configuration
โ”œโ”€โ”€ background.js       # Background service worker & auto-sync alarms
โ”œโ”€โ”€ feeds.js            # Multi-source parser (Disclose.io, H1, Bugcrowd, etc.)
โ”œโ”€โ”€ popup.html          # Cyber-obsidian bento grid dashboard
โ”œโ”€โ”€ popup.css           # Glassmorphic responsive dark stylesheet
โ”œโ”€โ”€ popup.js            # Reactive state, token search & clipboard integration
โ”œโ”€โ”€ icons/              # Extension brand assets (16px, 48px, 128px)
โ”œโ”€โ”€ assets/images/      # Interface preview screenshots and hero banner
โ””โ”€โ”€ dist/               # Packaged production zip release

๐Ÿค Contributing & License

Contributions, feedback, and feed additions are welcome! Open an issue or pull request.
Licensed under the MIT License.