{"repo":"hahwul/dalfox","free":true,"listed":false,"github":"https://github.com/hahwul/dalfox","clone":"git clone https://github.com/hahwul/dalfox.git","description":"🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.","language":"Rust","stars":5238,"topics":["xss","security","bugbounty","bugbounty-tool","xss-scanner","devsecops","hacktoberfest","rust"],"license":"MIT","category":"security-tools","readme_excerpt":"Looking for the Go (v2.x) version? Dalfox v3 is a complete rewrite in Rust. The Go codebase is preserved on the v2 branch and continues to receive security backports. See SECURITY.md for the support policy, and the migration guide for what changed in v3. Dalfox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities. Key features Subcommands: scan (URL / file / pipe / raw-HTTP, auto-detected), server , payload , mcp Discovery: Parameter analysis, static analysis, BAV testing, parameter mining XSS Scanning: Reflected, Stored (SXSS), DOM-based, with optimization and DOM/AST verification WAF: Fingerprinting with confidence scoring, bypass tracking, and tunable --waf-min-confidence HTTP Options: Custom headers, cookies, methods, proxy, and more Output: JSON/JSONL/Plain/Markdown/SARIF/TOML formats, silence mode, detailed reports Extensibility: REST API, MCP stdio server, custom payloads, remote wordlists And the various options required for the testing :D Installation Homebrew (macOS/Linux) Snapcraft (Ubuntu) Arch Linux (AUR) See the Installation guide for manual build instructions. Nixpkgs (NixOS) A package is available for Nix or NixOS users. Keep in mind that the latest releases might only be present in the unstable channel. Nix Flakes For Nix users with flakes enabled: Se","default_branch":null,"files":null,"tree":[],"storefront":"/r/hahwul","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/hahwul/dalfox/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}