Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

SiteMapper Pro

Recon & Discovery Free · No sign-up

Turn a flat list of URLs into 4 visualisations: hierarchical tree, sortable flat list, path-pattern frequency view and per-host stats. Auto-receives handoffs from Wayback / URL Extractor / Subdomain Discovery.

Try it now No sign-up required. Runs entirely in your browser.
URL list one URL per line · auto-prepends https:// · up to 80,000 lines · accepts handoff from Wayback / URL Extractor / Subdomain

What is SiteMapper Pro?

SiteMapper Pro takes the messy URL lists you collect during recon and structures them four different ways so the application surface becomes obvious. Paste a list (or accept a handoff from another tool) and instantly see the host and path tree, a sortable flat view with category badges, a pattern-frequency view that collapses /users/1, /users/2 and /users/3 into /users/{id}, and a per-host stats panel.

Everything runs client-side in your browser. URLs never leave your machine, and the tool chews through tens of thousands of Wayback URLs without breaking a sweat.

What it does

  • 4 view modes: hierarchical tree, sortable flat list, path-pattern frequency, per-host stats.
  • 10 categories: All URLs, API endpoints, Auth paths, with params, JS, Sensitive paths, Sensitive files, Backups, Documents, JSON/XML data. Switch with `1`-`9`.
  • Extension breakdown chips above the tree - click .php / .env / .json etc. to slice the visible set.
  • ID clustering (toggle): `/users/1`, `/users/2`, `/users/3` collapse to `/users/{id}` so identical patterns group together. Also handles UUIDs, hashes, years and locales.
  • Per-host stats panel: URL count, average and max path depth, top extensions per host.
  • Advanced filtration: regex (`re:^/api/v\d+`), exclude (`-static`), host pattern (`host:api.*`), depth (`depth:>=3`). Combine with spaces.
  • Sensitive highlighting: admin / login / api / upload / debug / .git / .env segments surface in amber in the tree; sensitive files (.sql / .env / .bak / .pem / .key) get a red flag in the flat view.
  • Per-leaf actions: copy URL, view archive replay, send to ProbeMaster.
  • Saved URL lists in localStorage with quick recall.
  • Auto-handoff IN/OUT: accepts URL lists from Wayback, URL Extractor and Subdomain Discovery. Pushes the filtered set to ProbeMaster, Takeover Scan, Security Headers, DNS Recon Pro and Vulnerability Scanner.
  • Subdomain handoff button: when 2+ hosts are detected, one click sends them to Subdomain Discovery.
  • Keyboard shortcuts: `/` filter, `e` expand all, `c` collapse all, `t`/`f`/`p`/`s` switch view, `1`-`9` switch category.
  • Open visible in tabs (capped at 12 with confirmation).
  • CSV / Markdown / TXT export.

Where it fits in your workflow

  • Make sense of tens of thousands of URLs from Wayback or a crawler.
  • Spot interesting branches (admin, api, internal, backups, debug) at a glance via the colour-coded tree.
  • See the frequency-grouped path patterns first to choose what to test (test one URL per pattern, not 100 IDs).
  • Drill in by host using the stats view to find the highest-density target.
  • Send the filtered set to ProbeMaster to probe alive, or to Takeover Scan to check for dangling endpoints.
Want more?

This one is free in your browser. Sign up for server-side recon, scan history, and projects.

Create free account Sign in

At a glance

CategoryRecon & Discovery
RunsIn your browser
Token cost Free - no tokens
Access No login needed
Status● Live

Frequently asked questions

Is my URL list sent to the server?

No. SiteMapper Pro runs entirely in your browser. Nothing is uploaded, nothing is logged, and there is no token cost.

Will it cope with a huge Wayback dump?

Yes. The build path dedupes, the tree caps rendering at 6,000 nodes for responsiveness, the flat view caps at 2,000 rows, filtering is debounced, and the full URL set is always available via Copy URLs or export.

What does the ID-clustering toggle do?

When on, numeric IDs, UUIDs, hashes, years and locale codes in URL paths are replaced with placeholders like `{id}`, `{uuid}`, `{hash}` so URLs that share the same shape group together. The pattern frequency view shows you which patterns repeat most.

How do the handoffs work?

Every tool that produces a host or URL list shares it through the Continue-recon pipeline. Click a Continue-recon suggestion (or an in-tool pivot button) and the current visible list is carried into the next tool: its input pre-fills and a banner offers a one-click Run. Large lists are trimmed to the target tool’s capacity and the banner tells you how many were imported. Nothing is uploaded.

Other free tools you might like

Explore more tools →