Automated security tools designed to detect and identify cross-site scripting vulnerabilities within web application codebases.
OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.
OWASP ZAP is a comprehensive dynamic application security testing tool that provides automated crawling, payload injection, and XSS detection, making it a flagship solution for integrating security scanning into CI/CD pipelines.
Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t
Dalfox is a specialized automated scanner built specifically for detecting and verifying XSS vulnerabilities, offering robust features like payload mutation, DOM analysis, and CI/CD-ready reporting that align perfectly with your requirements.
XSStrike is an automated security scanning engine designed for web application discovery, input
XSStrike is a specialized security scanner focused on detecting and exploiting XSS vulnerabilities through advanced payload injection and filter bypass techniques, though it lacks the broad, multi-vulnerability scope of a general-purpose web application scanner.
Arachni is a dynamic application security testing vulnerability scanner and web application security tool. It functions as a distributed web audit framework that performs active and passive audits to identify security flaws such as SQL injection and cross-site scripting. The project features a JavaScript-aware web crawler that executes scripts and monitors DOM changes to analyze modern dynamic web applications. It utilizes server platform fingerprinting to target compatible security payloads and provides a grid-based system to distribute scanning workloads across multiple nodes. The tool cov
Arachni is a comprehensive dynamic application security testing framework that performs automated crawling, payload injection, and XSS detection, making it a direct fit for your security scanning requirements.
Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology fingerprinting. It identifies common security flaws through automated scanning and semantic analysis, while verifying findings via a custom proof-of-concept execution engine. The system distinguishes itself with a containerized vulnerability testbed used to deploy pre-configured vulnerable applications. This environment allows for the simulation of specific vulnerabilities and edge-case scenarios to validate scanner accuracy and eliminate false positives. The platform covers a bro
Xray is a comprehensive web vulnerability scanner that features automated crawling, dynamic analysis, and a dedicated engine for verifying XSS and other security flaws, making it a direct match for your requirements.
XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.
XSStrike is a specialized security scanner that focuses on detecting and testing XSS vulnerabilities through advanced fuzzing and payload injection, making it a highly relevant tool for your security testing needs.
Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno
Strix is an automated security research and vulnerability scanning platform that provides the necessary dynamic analysis, headless browser automation, and CI/CD integration to identify XSS and other web vulnerabilities.