⚡ XSS Hunter

⚡ XSS Hunter

Your Injection Payloads

Use one of these script tags as your XSS payload. Each tag has a unique ID so fires are correlated back to the specific injection point.

Profile

Probe settings

Notifications

Invite tokens

Generate single-use tokens to invite other users (when self-registration is off).

Chainload modules

Stage-2 JS modules delivered to a fire via /chain/<injection_id>. Modules are filtered by URL and CSP patterns at delivery time — only matching enabled modules run.


+ New module

API tokens

Long-lived bearer tokens for the xsshunter CLI and any programmatic client. Send as Authorization: Bearer <token>. The plaintext is shown once at creation — copy it now.