NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security researchers and penetration testers discover and validate blind XSS vulnerabilities by capturing detailed information when payloads execute on target systems.
☆34Jan 14, 2026Updated 6 months ago
Alternatives and similar repositories for nexss
Users that are interested in nexss are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple XSS vulnerability checker tool very useful with xsschecker.☆28Nov 21, 2025Updated 8 months ago
- DursGo - The Go-Powered Web Application Scanner - With AI-Powered Analysis☆71Apr 21, 2026Updated 3 months ago
- Open-source stealer logs parser and visualization dashboard that structures and presents log data to facilitate analysis.☆94Jun 18, 2026Updated last month
- Go static taint-analysis engine that finds vulnerabilities in WordPress plugins — WordPress-aware (capability tiers, nonce≠authz, REST/AJ…☆20Jun 6, 2026Updated last month
- AI exploit simulation and continuous security pipeline for LLM apps and AI agents☆16Mar 16, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- gosqli is a fast and simple tool for detecting blind SQL injection vulnerabilities. It supports scanning URLs with custom payloads, paral…☆19Jun 22, 2026Updated last month
- A fast and efficient subdomain hijacking scanner that checks for takeover vulnerabilities by matching HTTP response bodies against predef…☆31Apr 12, 2026Updated 3 months ago
- Burp plugin for jxscout☆23May 12, 2025Updated last year
- ☆29Mar 3, 2022Updated 4 years ago
- miscellaneous sploit scripts/hacks☆18Feb 3, 2025Updated last year
- Collection of rules for Static Application Security Testing (SAST) with Semgrep☆13Apr 16, 2025Updated last year
- Open-source passive reconnaissance and exposure discovery tool that leverages VirusTotal and the Wayback Machine to uncover subdomains, U…☆146Jun 23, 2026Updated last month
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆31Oct 23, 2025Updated 9 months ago
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆38Jun 18, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ParamScan is a chrome extension for finding reflected parameters in a webpage.☆93Jan 11, 2025Updated last year
- Multi-agent AI system using GPT-4o, DeepSeek v3, and Llama 3.3 to detect if CVE vulnerabilities were exploited as zero-days. Analyzes…☆20Feb 13, 2026Updated 5 months ago
- vulntechfinder is a powerful security tool that automates vulnerability scanning based on technology stack detection. It intelligently pr…☆16Apr 12, 2026Updated 3 months ago
- xsschecker tests endpoints for reflected XSS by injecting payloads and checking responses. It prints vulnerable if the payload is reflect…☆38Nov 3, 2025Updated 8 months ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆61Apr 13, 2025Updated last year
- Lightweight reflection scanner☆20Aug 31, 2025Updated 10 months ago
- Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.☆278Jun 6, 2026Updated last month
- HaXder is an advanced, asynchronous reconnaissance framework for security researchers. Discover subdomains, map attack surfaces, fingerpr…☆48Jul 1, 2026Updated 3 weeks ago
- Subdosec is a fast, accurate subdomain takeover scanner with no false positives. It also offers a database of sites vulnerable to subdoma…☆64May 28, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Echo Electronic Magazine (Issue 1 - 31)☆51Jun 11, 2017Updated 9 years ago
- A lightweight Python tool to analyze PCAP files and generate network traffic reports. It detects traffic patterns, security concerns, and…☆19Sep 25, 2024Updated last year
- A tool for listing and extracting installed Android APKs and decrypted iOS IPAs (plus app storage) from rooted or jailbroken devices.☆39May 31, 2026Updated last month
- A fake DNS server for malware analysis written in Python3☆10Aug 14, 2022Updated 3 years ago
- ✨ Open-source AI hackers for your apps 👨🏻💻☆34Sep 9, 2025Updated 10 months ago
- ☆31Jan 19, 2026Updated 6 months ago
- A basic Android background service that connects to a remote server, executes commands, and returns encrypted output. Disguised as a syst…☆27Aug 2, 2025Updated 11 months ago
- URILoot is a browser extension designed for Bug Bounty Hunters and Pentesters. Makes fetching uris easy from various sources.☆64Feb 15, 2026Updated 5 months ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆46Jun 3, 2024Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Official API Documentation☆34Updated this week
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆264Mar 28, 2026Updated 4 months ago
- Sharing Session Python.id Jakarta X Indigo X Alibaba Cloud☆19Mar 19, 2025Updated last year
- 必应每日壁纸数据采集脚本、必应壁纸历史数据API和必应壁纸在线浏览。☆10Dec 31, 2020Updated 5 years ago
- Find open storage buckets and accessible files across Amazon Web Services, Google Cloud, Microsoft Azure, and Digital Ocean simultaneousl…☆20Jan 15, 2025Updated last year
- My-Course-Materials☆33Nov 29, 2023Updated 2 years ago
- COLI (Command Orchestration & Logic Interface) – A visual orchestration layer for EWE, built for bug bounty automation. Create and run CL…☆35Oct 15, 2025Updated 9 months ago