epsylon/xsser
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. observed · 2026-08-28
Health v2 · maintenance only
82/100
- Activity 91
- Release rhythm 60
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 5009
- days_rel: 55
- days_push: 55
- n_releases_24m: 1
Adoption not part of the score
1461 stars · 264 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in web applications. It ships with over 1500 attack vectors, WAF bypassers, context-aware finding validation, and PDF/XML/JSON reporting.
Use cases
- find xss vulnerabilities in a website
- test if a web app is vulnerable to cross-site scripting
- bypass WAF filters during a pentest
- fuzz a URL with XSS payloads
- generate a PDF report of XSS findings
- scan for DOM-based XSS
- check if XSS injections actually execute in a browser
When to choose
- you need a dedicated, mature XSS testing tool with a large payload library
- you must evade common WAFs like Cloudflare, Akamai, or ModSecurity during authorized testing
- you want automated verification of XSS findings to cut false positives
- you need machine-readable (JSON/XML) or PDF vulnerability reports
When to avoid
- you need a general-purpose web vulnerability scanner covering SQLi, SSRF, etc.
- you are looking for a defensive tool to fix XSS rather than exploit it
- your target is not a web application
- you require a permissive open-source license (the repo has no license)
Facets
framework · maturity active
penetration-testing security web-scraping http-client cli security penetration-testing web-development windows python cli xss cross-site-scripting waf-bypass vulnerability-scanning fuzzing pentesting tor reporting linux macos
2 sources
- readme: https://github.com/epsylon/xsser · fetched 2026-08-28 · fa6639eba76d
- homepage: https://xsser.03c8.net · fetched 2026-08-29 · c5a6ece6b9d2
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| epsylon/xsser | main | 82 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem