# chaitin/xray

一款长亭自研的完善的安全评估工具，支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

Repository: https://github.com/chaitin/xray
Canonical: https://ross.abutalabs.com/products/xray
Homepage: https://docs.xray.cool
Language: Vue
License: NOASSERTION
License Family: other
Topics: security, vulnerability, vulnerability-scanner, passive-vulnerability-scanner, xss, sqlinjection, poc
Last push: 2024-10-29T16:15:53+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2641, "days_push": 673, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 11720, forks 1875 (observed 2026-08-28T04:10:49.580746+00:00)

## What it is
xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporting active crawling, passive proxy scanning, and custom PoC plugins. The core binary is closed-source and distributed as a download; the repository mainly hosts community-contributed PoCs.

## Use cases
- scan a website for xss and sql injection vulnerabilities
- run a passive vulnerability scanner through an http proxy
- run custom poc scripts against web targets
- assess web app security before a pentest
- crawl a site and automatically detect vulnerabilities
- scan a single url for common web security issues

## When to choose
- you need a free, powerful web vulnerability scanner with active and passive modes
- you want community-contributed PoC plugins for emerging vulnerabilities
- you are a security professional doing authorized web assessments

## When to avoid
- you need fully open-source code you can audit or modify
- you have not read and agreed to the license terms, which restrict usage
- you need source-code scanning rather than web application scanning

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, security, penetration-testing, web-scraping
- domain: security, penetration-testing, web-development
- platform: cli, windows
- tags: vulnerability-scanner, poc, xss, sqli, passive-scanning, closed-source-binary, linux, macos

## Member repositories
- chaitin/xray (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:49.580746+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:15:22.767115+00:00, confidence not recorded.
  - readme: https://github.com/chaitin/xray (fetched 2026-08-28T04:10:49.580746+00:00, sha 7ae299b592ef)
  - homepage: https://docs.xray.cool (fetched 2026-08-29T08:13:57.424764+00:00, sha 7639cd595674)
  - site_page: https://docs.xray.cool/ (fetched 2026-08-29T08:13:57.434200+00:00, sha 7639cd595674)
- Data as of 2026-08-30T08:39:29.467469+00:00.
