XSSer is an automatic tool for pentesting XSS attacks against different applications. It is designed to identify and exploit XSS vulnerabilities in web applications. XSSer provides a comprehensive set of features to help you identify and exploit XSS vulnerabilities, including a built-in proxy server, a web crawler, and a set of pre-defined payloads. With XSSer, you can easily identify and exploit XSS vulnerabilities in web applications, making it an essential tool for any penetration tester or security researcher.
FEATURES
SIMILAR TOOLS
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
APKiD is a tool that identifies compilers, packers, obfuscators, and other weird stuff in APK files.
A deliberately vulnerable Java web application designed for educational purposes to teach web application security concepts and common vulnerabilities.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
A modular Python tool that obfuscates Android applications by manipulating decompiled smali code, resources, and manifest files without requiring source code access.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.