// the find
nahamsec/JSParser
JSParser is a small Python 2.7 app that runs a Tornado server on localhost:8008. You give it a JavaScript file, it beautifies the code with jsbeautifier, and it lists the relative URLs it finds. It is aimed at bug bounty hunters and appsec people who want a quick list of AJAX endpoints buried in a site's JS bundles.
The scope is narrow and the README says exactly what it does, so it is easy to judge and easy to try. Beautifying minified JS before extracting paths is the right order, since most endpoints in production bundles are otherwise hard to read. Bundling safeurl.py and listing it as a dependency suggests the author thought about fetching arbitrary target URLs safely. A Dockerfile is included, which avoids the Python 2.7 setup for anyone who just wants to run it.
Python 2.7 reached end of life in January 2020, so running this on a current system means an old interpreter or Docker, and the code gets no security fixes from the wider ecosystem. The last push was in November 2023 and the changelog is a single line, so treat it as a snapshot rather than a maintained tool. A static pass like this only sees relative URLs, as the README says, so absolute URLs and endpoints assembled at runtime or loaded by a second-stage script will be missed. The output goes to a browser page on localhost, and the README mentions no CLI or machine-readable output, which makes it awkward to feed into a recon pipeline.