Ross ROSS = Recommend OSS · open-source software intelligence for agents

epsylon/xsser

Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. observed · 2026-08-28

github.com/epsylon/xsser · homepage · Python observed · 2026-08-28

Health v2 · maintenance only

82/100

  • Activity 91
  • Release rhythm 60
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 5009
  • days_rel: 55
  • days_push: 55
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1461 stars · 264 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in web applications. It ships with over 1500 attack vectors, WAF bypassers, context-aware finding validation, and PDF/XML/JSON reporting.

Use cases

  • find xss vulnerabilities in a website
  • test if a web app is vulnerable to cross-site scripting
  • bypass WAF filters during a pentest
  • fuzz a URL with XSS payloads
  • generate a PDF report of XSS findings
  • scan for DOM-based XSS
  • check if XSS injections actually execute in a browser

When to choose

  • you need a dedicated, mature XSS testing tool with a large payload library
  • you must evade common WAFs like Cloudflare, Akamai, or ModSecurity during authorized testing
  • you want automated verification of XSS findings to cut false positives
  • you need machine-readable (JSON/XML) or PDF vulnerability reports

When to avoid

  • you need a general-purpose web vulnerability scanner covering SQLi, SSRF, etc.
  • you are looking for a defensive tool to fix XSS rather than exploit it
  • your target is not a web application
  • you require a permissive open-source license (the repo has no license)

Facets

framework · maturity active

penetration-testing security web-scraping http-client cli security penetration-testing web-development windows python cli xss cross-site-scripting waf-bypass vulnerability-scanning fuzzing pentesting tor reporting linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
epsylon/xssermain82

For agents

markdown · JSON · MCP: product_card(name="epsylon/xsser")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem