Ross ROSS = Recommend OSS · open-source software intelligence for agents

firesunCN/BlueLotus_XSSReceiver

None observed · 2026-08-28

github.com/firesunCN/BlueLotus_XSSReceiver · JavaScript · GPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3978
  • days_rel: n/a
  • days_push: 1308
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1623 stars · 972 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BlueLotus_XSSReceiver is a self-hosted XSS data receiving platform written in PHP and JavaScript, designed for CTF practice and security learning. It requires no database, records all incoming request data (GET, POST, cookies, headers, client info), and lets users manage XSS JavaScript payloads with templates, an editor, and keep-session functionality.

Use cases

  • receive and log XSS payload callbacks during CTF challenges
  • capture cookies and session data from XSS vulnerabilities in authorized tests
  • manage and generate XSS JavaScript payloads with templates
  • keep stolen sessions alive with keepsession
  • look up attacker-collected victim info by IP, browser, and OS

When to choose

  • you need a quick, database-free XSS receiver for CTF competitions
  • you want a simple PHP platform deployable on shared hosting
  • you need payload JS management with editing, formatting, and minification built in

When to avoid

  • you need a production-grade or actively developed security tool
  • your use case is unauthorized testing of systems you do not own
  • you require modern PHP frameworks or database-backed storage

Facets

application · maturity maintenance

security logging http-server security penetration-testing web-development php self-hosted xss ctf penetration-testing payload-management no-database web-server

1 source

Member repositories

RepositoryRoleHealth v2
firesunCN/BlueLotus_XSSReceivermain32

For agents

markdown · JSON · MCP: product_card(name="firesunCN/BlueLotus_XSSReceiver")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem