Ross ROSS = Recommend OSS · open-source software intelligence for agents

hahwul/dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation. observed · 2026-08-28

github.com/hahwul/dalfox · homepage · Rust · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 97
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 15.0
  • age_days: 2334
  • days_rel: 20
  • days_push: 8
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

5256 stars · 562 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of reflected, stored, and DOM-based XSS flaws. It runs as a CLI, REST API server, or MCP server, with WAF fingerprinting and bypass capabilities and output in JSON, SARIF, Markdown, and other formats.

Use cases

  • scan a URL for reflected XSS vulnerabilities
  • find stored XSS in web applications
  • detect DOM-based XSS with AST verification
  • fingerprint WAFs and generate bypass payloads
  • run XSS scanning in CI/CD pipelines with SARIF output
  • drive XSS scans from AI agents via MCP
  • mine and analyze parameters for injection points

When to choose

  • you need automated XSS detection during pentests or bug bounty hunting
  • you want DOM-verified findings with low false positives
  • you need scanner output in SARIF for security dashboards
  • you want a scriptable scanner that fits recon pipelines and proxies

When to avoid

  • you need a general-purpose web vulnerability scanner covering SQLi, SSRF, and other flaw classes
  • you require a GUI-driven scanning experience
  • you need passive-only scanning without active payload injection

Facets

cli-tool · maturity active

security penetration-testing vulnerability-scanning cli http-client mcp security penetration-testing web-development developer-tools windows cli cross-platform self-hosted xss-scanner bug-bounty waf-bypass sarif dom-verification rust pentesting devsecops command-line linux macos docker

5 sources

Member repositories

RepositoryRoleHealth v2
hahwul/dalfoxmain98

For agents

markdown · JSON · MCP: product_card(name="hahwul/dalfox")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem