Tool · activeactive
Dalfox
XSS scanner for reflected, stored and DOM input surfaces with structured PoC output.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsactive
More tools
- CommixactiveAutomated command-injection detection and exploitation.
- CorsyactiveScans for CORS misconfigurations.
- CRLFuzzactiveProbes for CRLF injection and HTTP response splitting.
- GhauriactiveFast automated SQL-injection detection and exploitation, an sqlmap alternative.
- gowitnessactiveHeadless screenshot capture of web targets.
- GraphQL CopactivePurpose-built GraphQL security audit for introspection, field suggestion, batching/DoS and CSRF issues.