Multi-mode input
URL, file, pipe and raw HTTP requests — the mode is auto-detected, no flags to fumble.
XSS Scanner · Automation
Dalfox
A powerful open-source XSS scanner and security utility, engineered in Rust for speed and built around automation — from parameter discovery to a verified proof-of-concept.

Capabilities
Dalfox pairs an aggressive testing engine with the ergonomics of a daily-driver CLI — point it at a target and it handles discovery, analysis and verification.
URL, file, pipe and raw HTTP requests — the mode is auto-detected, no flags to fumble.
Detects reflected, stored (SXSS) and DOM-based XSS in a single run.
Static and dynamic analysis surface hidden parameters before testing even starts.
Identifies the WAF in front of a target with confidence scoring and bypass tracking.
JSON, JSONL, plain, Markdown, SARIF and TOML — drops straight into DevSecOps.
REST API, MCP stdio server, custom payloads and remote wordlists.
Quickstart
Illustrative output — your mileage will vary by target.
Install Dalfox and run your first automated scan in seconds.