Item logo image for DOM XSS Highlighter — Pro

DOM XSS Highlighter — Pro

Item media 2 (screenshot) for DOM XSS Highlighter — Pro
Item video thumbnail
Item media 2 (screenshot) for DOM XSS Highlighter — Pro
Item video thumbnail
Item video thumbnail
Item media 2 (screenshot) for DOM XSS Highlighter — Pro

Overview

Highlights user-controlled reflections in DOM to help detect risky contexts. Run only on sites you own or may test.

DOM XSS Highlighter helps developers and security testers quickly spot user-controlled reflections inside a webpage’s DOM. By highlighting URL parameters, hash fragments, and other inputs that appear in risky contexts, it makes it easier to catch potential security issues during development and QA. ✨ Features • On-demand scanning (runs only when you click the extension) • Highlights user input in text, HTML, attributes, and scripts • Quick “rescan” and “clear” controls for fast testing • Click highlighted text to copy a structured JSON report • Local-only: no data ever leaves your browser 🛡️ Why install Speeds up manual DOM XSS testing Helps developers build safer web apps Simple interface with professional security look ⚠️ Note: For educational and authorized testing only. Use on websites you own or have explicit permission to test.

Details

  • Version
    1.0.0
  • Updated
    September 19, 2025
  • Size
    27.54KiB
  • Languages
    English
  • Developer
    Website
    Email
    0xgzofficial@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

Lyra

0.0

Lyra is a XSS automater and broken link checker.

Pathprobe

5.0

Asychronous multi-domain directory scanner

Hunter Search

5.0

Otimize buscas para pentest e bug bounty com dorks automáticos.

VAPT Assistant Pro+

0.0

Advanced VAPT toolkit with AI, security headers, WAF detection, DNS/WHOIS tools, subdomain scanner, and VirusTotal integration.

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Hack-Tools

4.6

The all in one Red team extension for web pentester

Subdomain Finder - Find Hidden Subdomains

5.0

The best Subdomain Finder tool for bug bounty hunters and security researchers. Find hidden subdomains quickly and easily.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

NavSec Vulnerability Scanner

5.0

Comprehensive security scanner with advanced XSS detection, API security analysis, and authentication testing

JS Recon Buddy

5.0

Analyze page scripts for bug bounty reconnaissance.

CyberPost Lab

5.0

A fully offline, browser-based HTTP request testing tool for cybersecurity researchers

Recon Buddy

5.0

Extract recon data like JWTs, API keys, parameters, and endpoints from visited pages.

Lyra

0.0

Lyra is a XSS automater and broken link checker.

Pathprobe

5.0

Asychronous multi-domain directory scanner

Hunter Search

5.0

Otimize buscas para pentest e bug bounty com dorks automáticos.

VAPT Assistant Pro+

0.0

Advanced VAPT toolkit with AI, security headers, WAF detection, DNS/WHOIS tools, subdomain scanner, and VirusTotal integration.

DIRFOX - Endpoint Fuzzer for Pentesters

0.0

Fuzz endpoints using custom or GitHub-hosted wordlists. Built for security researchers and pentesters.

Hack-Tools

4.6

The all in one Red team extension for web pentester

Subdomain Finder - Find Hidden Subdomains

5.0

The best Subdomain Finder tool for bug bounty hunters and security researchers. Find hidden subdomains quickly and easily.

Bug Hunter Toolkit

4.0

Professional bug hunting and penetration testing toolkit with essential security tools

Google apps