Ross ROSS = Recommend OSS · open-source software intelligence for agents

ssl/ezXSS

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. observed · 2026-08-28

github.com/ssl/ezXSS · homepage · PHP · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

64/100

  • Activity 91
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3467
  • days_rel: 409
  • days_push: 56
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

2330 stars · 385 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scripting vulnerabilities. When a payload fires, it captures page data (DOM, cookies, screenshots, storage) and alerts the user via email, Telegram, Slack, or Discord.

Use cases

  • test for blind XSS vulnerabilities
  • capture XSS reports during bug bounty hunting
  • get alerted when an XSS payload triggers
  • track persistent XSS sessions across pages
  • collect page DOM and screenshots from vulnerable pages
  • manage XSS payloads and reports with a team

When to choose

  • you need to detect blind XSS that fires long after injection
  • you want a self-hosted XSS reporting dashboard with alerts
  • you're a pentester or bug bounty hunter testing web apps

When to avoid

  • you need a general-purpose web vulnerability scanner
  • you lack a PHP server or domain to host it
  • you want automated scanning rather than payload-based detection

Facets

application · maturity active

security penetration-testing vulnerability-scanning web-framework http-server alerting logging security penetration-testing web-development developer-tools php self-hosted blind-xss xss-detection bug-bounty red-team payload-management dashboard web-server docker linux

2 sources

Member repositories

RepositoryRoleHealth v2
ssl/ezXSSmain64

For agents

markdown · JSON · MCP: product_card(name="ssl/ezXSS")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem