DOMXSS Scanner is an online tool to scan source code for DOM based XSS vulnerabilities. It allows you to upload your HTML, JavaScript, and CSS files to scan for potential vulnerabilities. The tool provides a detailed report of the findings, including the vulnerable code snippets and recommendations for remediation.
FEATURES
SIMILAR TOOLS
Threatspy is an application security testing platform that enables developers and security teams to discover, analyze, prioritize, and remediate vulnerabilities in web applications and APIs through an automated end-to-end process.
A brute-force protection middleware for express routes that rate-limits incoming requests.
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
Runtime application security platform that provides vulnerability management, patching, and threat detection at the application level during program execution.
An IDE-integrated AI security solution that detects, remediates, and educates about code vulnerabilities in real-time as developers write code.
A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.
Arnica is an application security platform that offers real-time scanning, risk mitigation, and management across various aspects of the software development lifecycle.
An educational codelab that demonstrates web application vulnerabilities including XSS, XSRF, and code execution attacks along with their corresponding defensive measures.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.