Pattern-based detection
Tests parameters with a tuned payload set to flag reflected XSS.
XSS Scanner · Ruby
A powerful XSS scanning and parameter-analysis tool and gem. Pattern-based detection plus a headless browser to confirm alert, confirm and prompt firings.
Capabilities
A long-running Ruby XSS scanner (now archived, succeeded by Dalfox) — pattern matching backed by real browser verification.
Tests parameters with a tuned payload set to flag reflected XSS.
A headless Selenium browser confirms real alert, confirm and prompt firings.
Built-in blind XSS testing, compatible with XSS Hunter, ezXSS and HBXSS.
Detects filtered rules — event handlers, HTML tags and special characters.
Reports reflection points, SQL errors and missing security headers.
Replay request and response files exported from Burp Suite or ZAP.
Quickstart
Illustrative output.
Install the XSpear gem, or try Dalfox for ongoing development.