Multi-mode input
URL, file, pipe and raw HTTP requests — the mode is auto-detected, no extra flags needed.
XSS Scanner · Automation
Dalfox
An open-source XSS scanner and security utility, written in Rust and built around automation — from parameter discovery to a verified proof-of-concept.

Capabilities
Point Dalfox at a target and it handles discovery, analysis and verification, from a CLI you can live in every day.
URL, file, pipe and raw HTTP requests — the mode is auto-detected, no extra flags needed.
Detects reflected, stored (SXSS) and DOM-based XSS in a single run.
Static and dynamic analysis surface hidden parameters before testing even starts.
Identifies the WAF in front of a target with confidence scoring and bypass tracking.
JSON, JSONL, plain, Markdown, SARIF and TOML, ready for DevSecOps pipelines.
REST API, MCP stdio server, custom payloads and remote wordlists.
Quickstart
Illustrative output — your mileage will vary by target.
Install Dalfox and run your first automated scan in seconds.