DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
-
Updated
Jul 22, 2025 - JavaScript
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Awesome XSS stuff
XSS'OR - Hack with JavaScript.
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
A container repository for my public web hacks!
A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
Use DOMPurify on server and client in the same way
🕷️ XSS Listener is a penetration tool for easy to steal data with various XSS.
Proactively protect your Node.js web services
The Serverless Blind XSS App
Mike North's Web Security Course
Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.
This extension will help you to detect GET/POST based XSS vulnerability in any website easily
Add a description, image, and links to the xss topic page so that developers can more easily learn about it.
To associate your repository with the xss topic, visit your repo's landing page and select "manage topics."