dalfox
« Back to VersTracker
Description:
XSS scanner and utility focused on automation
Type: Formula  |  Latest Version: 2.12.0@0  |  Tracked Since: Dec 17, 2025
Links: Homepage  |  @hahwul  |  formulae.brew.sh
Category: Security
Tags: xss security-scanner web-security automation penetration-testing
Install: brew install dalfox
About:
Dalfox is a powerful XSS scanner and utility designed for automation in security testing. It analyzes web applications to detect and validate Cross-Site Scripting vulnerabilities efficiently. The tool supports various modes including parameter analysis, URL crawling, and WAF bypassing to streamline the identification of potential security flaws.
Key Features:
  • Automated parameter analysis and XSS detection
  • Built-in WAF bypass techniques
  • Support for reflected, stored, and DOM-based XSS scanning
  • Integration with CI/CD pipelines for continuous security testing
Use Cases:
  • Performing quick security audits on web applications
  • Integrating XSS scanning into automated CI/CD security checks
Alternatives:
  • XSStrike – More focused on manual testing and advanced detection techniques
  • Nuclei – Broader vulnerability scanner with XSS templates
Version History
Detected Version Rev Change Commit
Oct 10, 2025 12:04pm 0 VERSION_BUMP 120e1b09
Sep 14, 2025 6:43am 0 VERSION_BUMP 918d656a