| Scanner | Version | Build | Vendor | |
| XSSer | 1.5 | 1 | psy |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 1.5 (Beta)
Build 1 | GPL3 Python 2.5.x | 24-02-2011 |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Complex | Simple | Unstable | Fast |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 4 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 4 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 2 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| Exploitation features, Rough manual crawling support due to the URL file parsing feature (No FORM submission), GET/POST coverage (rough POST coverage for single URL scans). |
| Detection Accuracy | Chart | ||||
| 34.85% Detection Rate 57.14% False Positives | (23/66) (4/7) |
| Plenty of different XSS flavors. |
| Exploitation features, Rough manual crawling support due to the URL file parsing feature (No FORM submission), GET/POST coverage (rough POST coverage for single URL scans). |
| The tool implements some useful and even rare features (DOM XSS, etc), but is very difficult to execute it in an effective manner on a large scale application, and naturally, as an alpha product, its prone to various bugs. |