Tool · dast/web-app-scanneractivehigh-riskdual-uselicence
XSSer
XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.
More tools
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Custom AI Agent (Burp)dast/web-app-scannerA Burp Suite extension (formerly Burp AI Agent) that integrates AI into web security testing: connects to 11 AI providers (Ollama, Claude, Gemini, OpenAI-compatible), exposes up to 59 MCP tools for external AI clients to drive Burp, includes passive/active scanners covering 62 vulnerability classes, and offers privacy modes with host anonymization and AES-256-GCM credential storage.
- OWASP ZAP (Zed Attack Proxy)dast/web-app-scannerOpen-source web-application security scanner and intercepting proxy with a large add-on marketplace (active/passive scan rules, AJAX/client spider, auth helper, automation framework, GraphQL/SOAP, SARIF reporting).
- XSRFProbedast/web-app-scannerA Python CSRF audit toolkit that crawls a target web app and runs 25+ checks for anti-CSRF token weaknesses, referer/origin validation bypasses and SameSite cookie issues, generating exploitable PoC payloads and JSON reports. GPLv3, v3.0.0, actively maintained.
- ZAP Extensionsdast/web-app-scannerThe official add-on repository for OWASP ZAP (Zed Attack Proxy), the open-source dynamic application security testing (DAST) scanner. Contains the modular add-ons (in the addOns directory, built with Gradle) that extend ZAP's active/passive scanning, fuzzing, and web-app testing capabilities; tagged appsec, security, and dast.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.