XSS Vulnerability Detector Online - Find Cross-Site Scripting Issues in Code

🛡 XSS Vulnerability Detector

Upload your code to detect potential cross-site scripting vulnerabilities

✓ JavaScript/DOM ✓ React/Vue/Angular ✓ JSP/PHP ✓ Python/Ruby
🔍
Drop your code file or ZIP here to scan
Supports: .js, .jsx, .ts, .tsx, .vue, .html, .jsp, .php, .py, .erb, .cshtml, .zip
📄 Selected:
Scanning...
⚠ Error

XSS Patterns Detected

This tool detects common XSS vulnerability patterns across multiple frameworks:

💻 DOM-based XSS

innerHTML, outerHTML, document.write, eval(), unsafe URL handling, jQuery .html() method

⚛ React

dangerouslySetInnerHTML usage without proper sanitization

💚 Vue.js

v-html directive with unsanitized user input

🔴 Angular

[innerHTML] binding, bypassSecurityTrust* functions

☕ JSP/Java

Unencoded request parameters, scriptlet output without escaping, EL expressions

🐘 PHP

Echo/print without htmlspecialchars, direct superglobal output

Encoding and Data Utilities

Encode, decode, measure sizes, and transform common formats.

Search Tutorials