All projects

XSS Scanner · Automation

Dalfox

An open-source XSS scanner and security utility, written in Rust and built around automation — from parameter discovery to a verified proof-of-concept.

Rust 5k MIT
Dalfox logo
5K+ GitHub stars
4 Input modes
6 Output formats
3 XSS vectors

Capabilities

From discovery to a verified PoC

Point Dalfox at a target and it handles discovery, analysis and verification, from a CLI you can live in every day.

Multi-mode input

URL, file, pipe and raw HTTP requests — the mode is auto-detected, no extra flags needed.

Reflected · Stored · DOM

Detects reflected, stored (SXSS) and DOM-based XSS in a single run.

Parameter mining

Static and dynamic analysis surface hidden parameters before testing even starts.

WAF fingerprinting

Identifies the WAF in front of a target with confidence scoring and bypass tracking.

Pipeline-native output

JSON, JSONL, plain, Markdown, SARIF and TOML, ready for DevSecOps pipelines.

Built to extend

REST API, MCP stdio server, custom payloads and remote wordlists.

Quickstart

From install to a verified PoC in one command

zsh
$ brew install dalfox
# scan a URL and mine DOM parameters
$ dalfox url https://target.tld/?q=1 --mining-dom
[*] Detected WAF: Cloudflare (confidence 0.92)
[POC][R] https://target.tld/?q=%22%3E%3Csvg/onload=alert(1)%3E
[*] 1 verified XSS · scanned in 2.4s

Illustrative output — your mileage will vary by target.

Run your first scan.

Install Dalfox and run your first automated scan in seconds.