# terjanq/Tiny-XSS-Payloads

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Repository: https://github.com/terjanq/Tiny-XSS-Payloads
Canonical: https://ross.abutalabs.com/products/tiny-xss-payloads
Homepage: https://tinyxss.terjanq.me/
Language: JavaScript
License Family: other
Topics: xss, javascript, html, ctf, bugbounty, payloads
Last push: 2024-11-29T23:58:23+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2246, "days_push": 642, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2386, forks 218 (observed 2026-08-28T04:06:42.692831+00:00)

## What it is
A curated collection of minimal cross-site scripting (XSS) payloads organized by injection context, with an interactive demo site. It serves as a reference for security researchers, bug bounty hunters, and CTF players.

## Use cases
- find short xss payloads for a bug bounty report
- bypass csp with a tiny xss payload
- learn xss techniques for ctf challenges
- reference payloads that work inside innerhtml
- find xss payloads for different browser contexts

## When to choose
- you need compact XSS payloads for specific injection contexts like innerHTML, iframes, or style tags
- you are doing bug bounty, pentesting, or CTF work involving XSS
- you want a browsable reference of browser-specific XSS tricks

## When to avoid
- you need a comprehensive XSS scanner or automated testing tool
- you want general web security hardening guidance or defensive libraries
- you need a maintained software library with a license for production use

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, vulnerability-scanning
- domain: security, web-development, penetration-testing
- platform: browser
- tags: xss, payloads, bugbounty, ctf, cheatsheet, cross-site-scripting, web-server

## Member repositories
- terjanq/Tiny-XSS-Payloads (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:42.692831+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:34:36.987385+00:00, confidence not recorded.
  - readme: https://github.com/terjanq/Tiny-XSS-Payloads (fetched 2026-08-28T04:06:42.692831+00:00, sha 804f347c1a62)
  - homepage: https://tinyxss.terjanq.me/ (fetched 2026-08-29T10:15:45.000267+00:00, sha 6dc793552c96)
- Data as of 2026-08-30T08:39:29.467469+00:00.
