Search seven userscript catalogs at once. Compare trust evidence and inspect metadata before you install.
Open ScriptHunt · Try a YouTube search · Download the latest release
ScriptHunt is a private, installable web app for finding userscripts without checking one catalog at a time. It merges results in the browser, keeps the source attached to every record, and shows what it could verify. There is no account and no analytics.
- Search Greasy Fork, Sleazy Fork, GitHub, OpenUserJS, Userscript.Zone, ScriptCat, and GitHub Gists from one query.
- Compare popularity, freshness, permissions, source health, and scan results without losing provenance.
- Inspect userscript metadata and code patterns before opening an install URL. ScriptHunt never executes fetched scripts.
- Keep favorites, saved searches, installed records, and recent results in local browser storage.
| Compare candidates | Light theme |
|---|---|
![]() |
![]() |
Screenshots use fixed sample responses so the documented states remain reproducible.
The interface also includes dark, OLED black, and automatic themes. It works down to a 320 pixel viewport and can be installed as a Progressive Web App.
The hosted app is ready at sysadmindoc.github.io/UserScriptHunt. Enter a keyword, domain, or exact page URL. Results arrive progressively as each enabled source responds.
Useful query operators:
| Operator | Example | What it does |
|---|---|---|
site: |
site:youtube.com |
Finds scripts that target a domain |
author: |
author:PixelPilot |
Limits results to an author |
updated: |
updated:90d |
Limits results by age |
grant: |
grant:GM_xmlhttpRequest |
Filters by userscript permission |
Visible controls cover license, install count, catalog language, risk, and updated date. Search state can be shared through URL parameters.
ScriptHunt labels missing evidence instead of treating it as safe. A trust score combines the information that is available for a result, including source health, popularity, freshness, metadata quality, and an optional code scan.
The scanner fetches a userscript as text and checks metadata plus known risky patterns. It records the response URL, HTTP status, fetch time, content hash, and cache age. It does not run the code. A clean result means no configured pattern was found, not that the script is guaranteed safe. Read unfamiliar code and review requested permissions before installing it.
Dependency checks are also non-executing. They can verify declared hashes, flag floating URLs, and detect changed content for bounded @require and @resource requests.
| Source | Method | Route | Auth Required | CORS | Per-Page | Capabilities | Metadata |
|---|---|---|---|---|---|---|---|
| Greasy Fork | JSON API + by-site.json | direct | No | Native (*) |
100 | search, pagination, totals, site filter, install URLs | Installs, ratings, version, dates, license, author |
| Sleazy Fork | JSON API | direct | No | Native (*) |
100 | search, pagination, totals, site filter, install URLs | Installs, ratings, version, dates, license, author |
| GitHub | REST API v3 + Code Search | direct | Optional token | Native CORS | 30 | repository search, authenticated code search, pagination, totals | Stars, forks, language, license, dates |
| OpenUserJS | HTML scraping | custom/public proxy | No | Via proxy | 25 | search, pagination, install URLs | Name, author, install URL |
| Userscript.Zone | HTML scraping | custom/public proxy | No | Via proxy | 10 | search, pagination, install URLs | Name, description, install URL |
| ScriptCat | JSON API v2 | direct | No | Native CORS | 30 | search, pagination, totals, install URLs | Installs, ratings, version, dates, author |
| GitHub Gists | HTML scraping | custom/public proxy | No | Via proxy | 10 | search, pagination, install URLs | Name, author, install URL |
Sleazy Fork and GitHub Gists are off by default. GitHub repository search works without a token. An optional token enables higher limits and file-level code search, stays in session storage, and disappears when the browser tab closes.
OpenUserJS, Userscript.Zone, and Gist search need a CORS proxy. Public fallback services receive the target search or script URL. You can disable public fallback and configure the included allowlisted Cloudflare Worker from Diagnostics.
Open the hosted site in a browser with PWA support, then choose its install action. The installed app keeps the interface shell available offline. Recent cached searches can be reopened with their source and scan evidence.
To self-host the static app:
git clone https://github.com/SysAdminDoc/UserScriptHunt.git
cd UserScriptHunt
python -m http.server 8000Open http://localhost:8000. A local server is recommended because service workers do not run from file:// pages.
GitHub Pages can serve the repository directly from the main branch root. No build step is required.
Preferences and small lists use localStorage. Recent searches and scan records prefer IndexedDB, with a localStorage fallback. Imports are validated before they change data, and ScriptHunt creates a local recovery snapshot before replacing favorites or installed records.
Diagnostics can clear search and scan caches without removing favorites, installed records, saved searches, or credentials. Export important lists before clearing browser storage.
Install the pinned test dependency and run the local verification suite:
npm ci
npm run test:install
npm run qanpm run qa runs the package security audit, Worker tests, version and source documentation checks, and the browser suite. The browser tests mock catalog responses and run headlessly against the repository's local static server.
Regenerate the checked-in product images with:
npm run capture:marketingCreate the release ZIP and checksum with:
npm run release:packageThe app uses vanilla HTML, CSS, and JavaScript. Runtime fonts are vendored under the SIL Open Font License. The optional CORS proxy lives in cors-proxy/worker.js.
Built-in sources use a shared adapter contract. Each adapter returns normalized result and provenance records, so the search, filter, cache, and diagnostics layers do not need source-specific branches.
Custom sources can be added from Diagnostics with a versioned JSON manifest. The manifest declares a stable identifier, an HTTPS request template, response paths, field mappings, and strict time and size limits. Custom JavaScript is never evaluated.
UserScript-Finder adds a menu command to Tampermonkey and Violentmonkey for finding scripts made for the page you are viewing. ScriptHunt is the broader catalog search and comparison app.
The three original magnifier concepts are preserved in assets/brand/concepts. The folder's selection.json records the approved code-brace direction and points to the untouched source master. Production-ready transparent artwork remains in assets/brand and the PWA icon files at the repository root.
ScriptHunt is available under the MIT License.




