pr0h0
Security Tools

XSS Go Scanner

A small Go command-line tool that uses a real browser to check whether web applications safely handle untrusted input, for authorized testing.

XSS Go Scanner is a compact command-line tool written in Go for checking how web applications handle untrusted input during authorized security testing.

Many simple scanners only look at the raw HTML a server returns, which misses problems that only appear once a page is rendered and its scripts run. This tool drives a real browser through Playwright instead, so a result reflects what actually happens in the page rather than what the response text suggests.

It is a focused experiment from January 2025: it runs from the command line, supports both GET and POST requests, and keeps scanning logic, request handling and utilities in separate packages. It is intended only for applications you are authorized to test.

Key features

  • Single Go binary with a simple command-line interface
  • Checks results in a real browser via Playwright, not just raw HTML responses
  • Supports GET and POST requests
  • Small, modular codebase separating scanning, request handling and utilities