NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security researchers and penetration testers discover and validate blind XSS vulnerabilities by capturing detailed information when payloads execute on target systems.
☆35Jan 14, 2026Updated 7 months ago
Alternatives and similar repositories for nexss
Users that are interested in nexss are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple XSS vulnerability checker tool very useful with xsschecker.☆28Nov 21, 2025Updated 9 months ago
- DursGo - The Go-Powered Web Application Scanner - With AI-Powered Analysis☆72Apr 21, 2026Updated 4 months ago
- Open-source stealer logs parser and visualization dashboard that structures and presents log data to facilitate analysis.☆96Jun 18, 2026Updated 2 months ago
- Go static taint-analysis engine that finds vulnerabilities in WordPress plugins — WordPress-aware (capability tiers, nonce≠authz, REST/AJ…☆21Jun 6, 2026Updated 3 months ago
- AI exploit simulation and continuous security pipeline for LLM apps and AI agents☆16Mar 16, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- gosqli is a fast and simple tool for detecting blind SQL injection vulnerabilities. It supports scanning URLs with custom payloads, paral…☆19Jun 22, 2026Updated 2 months ago
- A fast and efficient subdomain hijacking scanner that checks for takeover vulnerabilities by matching HTTP response bodies against predef…☆44Apr 12, 2026Updated 4 months ago
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- miscellaneous sploit scripts/hacks☆18Feb 3, 2025Updated last year
- ☆29Mar 3, 2022Updated 4 years ago
- Collection of rules for Static Application Security Testing (SAST) with Semgrep☆13Apr 16, 2025Updated last year
- Open-source passive reconnaissance and exposure discovery tool that leverages VirusTotal and the Wayback Machine to uncover subdomains, U…☆147Jun 23, 2026Updated 2 months ago
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆31Oct 23, 2025Updated 10 months ago
- Droid LLM Hunter is a tool to scan for vulnerabilities in Android applications using Large Language Models (LLMs).☆199Aug 31, 2026Updated last week
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 2 months ago
- Multi-agent AI system using GPT-4o, DeepSeek v3, and Llama 3.3 to detect if CVE vulnerabilities were exploited as zero-days. Analyzes …☆20Feb 13, 2026Updated 6 months ago
- ParamScan is a chrome extension for finding reflected parameters in a webpage.☆93Jan 11, 2025Updated last year
- xsschecker tests endpoints for reflected XSS by injecting payloads and checking responses. It prints vulnerable if the payload is reflect…☆38Nov 3, 2025Updated 10 months ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆61Apr 13, 2025Updated last year
- Lightweight reflection scanner☆20Aug 31, 2025Updated last year
- The First Open Source Bug Bounty Platform☆104Jul 28, 2026Updated last month
- vulntechfinder is a powerful security tool that automates vulnerability scanning based on technology stack detection. It intelligently pr…☆20Aug 23, 2026Updated 2 weeks ago
- Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.☆284Aug 12, 2026Updated 3 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- HaXder is an advanced, asynchronous reconnaissance framework for security researchers. Discover subdomains, map attack surfaces, fingerpr…☆49Jul 1, 2026Updated 2 months ago
- Subdosec is a fast, accurate subdomain takeover scanner with no false positives. It also offers a database of sites vulnerable to subdoma…☆63Aug 30, 2026Updated last week
- ✅ Experience the power of an automated Insecure Direct Object Reference (IDOR) vulnerability detection tool. Safeguard your applications …☆72Updated this week
- A lightweight Python tool to analyze PCAP files and generate network traffic reports. It detects traffic patterns, security concerns, and…☆19Sep 25, 2024Updated last year
- A tool for listing and extracting installed Android APKs and decrypted iOS IPAs (plus app storage) from rooted or jailbroken devices.☆39May 31, 2026Updated 3 months ago
- Give me your APK, I will give you framework name☆15May 6, 2026Updated 4 months ago
- ✨ Open-source AI hackers for your apps 👨🏻💻☆34Sep 9, 2025Updated 11 months ago
- SSLPinDetect is a tool for analyzing Android APKs to detect SSL pinning implementations by scanning for known patterns in decompiled code…☆87Sep 5, 2025Updated last year
- A basic Android background service that connects to a remote server, executes commands, and returns encrypted output. Disguised as a syst…☆28Aug 2, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆46Jun 3, 2024Updated 2 years ago
- Official API Documentation☆34Updated this week
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆268Mar 28, 2026Updated 5 months ago
- URILoot is a browser extension designed for Bug Bounty Hunters and Pentesters. Makes fetching uris easy from various sources.☆64Feb 15, 2026Updated 6 months ago
- Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).☆19Nov 19, 2024Updated last year
- Sharing Session Python.id Jakarta X Indigo X Alibaba Cloud☆19Mar 19, 2025Updated last year
- 必应每日壁纸数据采集脚本、必应壁纸历史数据API和必应壁纸在线浏览。☆10Dec 31, 2020Updated 5 years ago