{"adoption": {"forks": 222, "observed_at": "2026-08-28T04:04:38.076590+00:00", "stars": 1404}, "canonical_url": "https://ross.abutalabs.com/products/weaponised-xss-payloads", "card": {"archived": false, "artifact_type": "library", "description": "XSS payloads designed to turn alert(1) into P1", "domain": ["security", "web-development", "penetration-testing"], "enriched": true, "function": ["security", "penetration-testing"], "health_score": 20, "homepage": null, "language": "JavaScript", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["hakluke/weaponised-XSS-payloads"], "name": "hakluke/weaponised-XSS-payloads", "platform": ["browser"], "pushed_at": "2023-09-12T12:44:23+00:00", "repo": "hakluke/weaponised-XSS-payloads", "stars": 1404, "tags": ["xss-payloads", "bug-bounty", "exploitation", "javascript-payloads", "cms-exploits", "web-server"], "topics": [], "urls": [], "use_cases": ["upgrade XSS findings from medium to critical severity", "demonstrate account takeover via stored XSS in a pentest report", "create admin users through XSS on WordPress", "chain XSS bugs into P1 bug bounty reports", "show real security impact of reflected XSS vulnerabilities"], "what_it_is": "A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platforms when loaded via an XSS vulnerability. It helps pentesters and bug bounty hunters demonstrate real impact by chaining XSS into critical findings such as account takeover.", "when_to_avoid": ["you need a general XSS scanner or detection tool", "you are looking for XSS prevention or sanitization libraries", "you lack authorization to test the target system"], "when_to_choose": ["you need to prove business impact of an XSS bug in a pentest or bug bounty", "you are testing popular CMS platforms like WordPress for XSS escalation", "you want ready-made JavaScript payloads for authorized security testing"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/weaponised-xss-payloads", "repo": "hakluke/weaponised-XSS-payloads", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:38.076590+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:38:50.778244+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c97ce1efe21b926d285a1b6392c8cd2cf159107ced0d77cf0abbca19e05600cb", "fetched_at": "2026-08-28T04:04:38.076590+00:00", "kind": "readme", "missing": false, "url": "https://github.com/hakluke/weaponised-XSS-payloads"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2663, "days_push": 1086, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}