Web Tools DocGuides

How to use XSS Payload Auditor

Get the best out of XSS Payload Auditor: every option explained, a worked example, and what to check when the output is not what you expected.

Updated July 31, 2026

What it does

Inspect input strings and markup for high-risk XSS payload signatures. It runs entirely in your browser — your input never leaves your device.

Options

Every setting this tool exposes, straight from the code that validates it.

OptionTypeDefaultWhat it does
texttextPayload/string to audit for XSS risk patterns. Required.

Worked example

Run these settings on the tool page:

  • text: hello

You get:

{
  "score": 0,
  "verdict": "No common XSS signatures detected.",
  "findings": [],
  "recommendations": [
    "HTML-encode untrusted values before inserting them into the DOM.",
    "Avoid `innerHTML` for untrusted content; prefer `textContent` or safe templating.",
    "Use a restrictive Content Security Policy with nonces or hashes for scripts."
  ]
}

Troubleshooting

  • Nothing happens / the output stays empty. text is required — the tool waits until you provide it.
  • It is slow on very large input. Everything runs in your browser, so speed depends on your device. Very large inputs are best split up, or run through the API where the work happens on our servers.

Automating it

The same logic is available as a REST endpoint, so you can run it from a script, a CI job or your own app.

Bash
curl "https://api.toolsxpo.com/v1/xss-auditor" \
  -H "Authorization: Bearer $TOOLSXPO_KEY"

It costs 1 credit per successful call. See the full endpoint reference, or try it in the playground.

Tools covered here

XSS Payload Auditor

Security

security

Related