DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
-
Updated
Nov 10, 2025 - JavaScript
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Awesome XSS stuff
XSS'OR - Hack with JavaScript.
A container repository for my public web hacks!
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
The Serverless Blind XSS App
Mike North's Web Security Course
A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
Examples of security features (or mishaps) on web applications -- these are mostly examples and tutorials from the WASEC book.
XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts
This extension will help you to detect GET/POST based XSS vulnerability in any website easily
Add a description, image, and links to the xss topic page so that developers can more easily learn about it.
To associate your repository with the xss topic, visit your repo's landing page and select "manage topics."