#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

Web application security scanner created by lcamtuf for google - Unofficial Mirror
The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Default signature for Jaeles Scanner

automated web assets enumeration & scanning [DEPRECATED]

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

Detection for CVE-2025-53072 + CVE-2025-62481

An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.

To find HTML injection and XSS

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

XSSCon: Simple XSS Scanner tool

Vulnerability detection scripts for the n8n product.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Web Application Vulnerability Scanner.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

XSS spider - 66/66 wavsep XSS detected

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…