# epsylon/xsser

Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

Repository: https://github.com/epsylon/xsser
Canonical: https://ross.abutalabs.com/products/xsser
Homepage: https://xsser.03c8.net
Language: Python
License Family: other
Topics: xsser, pentesting, toolkit, xss, exploiting
Last push: 2026-07-09T17:33:34+00:00

## Health v2 (maintenance only)
Score: 82/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 91, release rhythm 60, longevity 100
- inputs: {"age_days": 5009, "days_push": 55, "days_rel": 55, "gap_med": null, "n_releases_24m": 1}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1461, forks 264 (observed 2026-08-28T04:04:47.549383+00:00)

## What it is
XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in web applications. It ships with over 1500 attack vectors, WAF bypassers, context-aware finding validation, and PDF/XML/JSON reporting.

## Use cases
- find xss vulnerabilities in a website
- test if a web app is vulnerable to cross-site scripting
- bypass WAF filters during a pentest
- fuzz a URL with XSS payloads
- generate a PDF report of XSS findings
- scan for DOM-based XSS
- check if XSS injections actually execute in a browser

## When to choose
- you need a dedicated, mature XSS testing tool with a large payload library
- you must evade common WAFs like Cloudflare, Akamai, or ModSecurity during authorized testing
- you want automated verification of XSS findings to cut false positives
- you need machine-readable (JSON/XML) or PDF vulnerability reports

## When to avoid
- you need a general-purpose web vulnerability scanner covering SQLi, SSRF, etc.
- you are looking for a defensive tool to fix XSS rather than exploit it
- your target is not a web application
- you require a permissive open-source license (the repo has no license)

## Facets
- artifact type: framework
- maturity: active
- function: penetration-testing, security, web-scraping, http-client, cli
- domain: security, penetration-testing, web-development
- platform: windows, python, cli
- tags: xss, cross-site-scripting, waf-bypass, vulnerability-scanning, fuzzing, pentesting, tor, reporting, linux, macos

## Member repositories
- epsylon/xsser (main) score 82

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:47.549383+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:35:19.978326+00:00, confidence not recorded.
  - readme: https://github.com/epsylon/xsser (fetched 2026-08-28T04:04:47.549383+00:00, sha fa6639eba76d)
  - homepage: https://xsser.03c8.net (fetched 2026-08-29T11:43:55.858443+00:00, sha c5a6ece6b9d2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
