DALFOX is an open-source security scanner focused on automated detection and verification of cross-site scripting vulnerabilities. Version 3 is implemented in Rust, while the earlier Go-based generation remains preserved on a separate branch. The tool can analyze URLs, files, piped input, and raw HTTP requests while examining parameters and possible injection points. Its engine covers reflected, stored, and DOM-based XSS together with static analysis and parameter discovery. WAF fingerprinting helps identify defensive filtering behavior, while multiple output formats support reporting and automation. Dalfox can also operate through a server mode, REST integrations, and an MCP interface. It is intended for authorized application-security testing, bug bounty work, and defensive vulnerability assessment.

Features

  • Reflected, stored, and DOM XSS detection
  • Parameter discovery and static analysis
  • WAF fingerprinting and analysis
  • URL, file, pipe, and raw HTTP input
  • JSON, Markdown, SARIF, and other reports
  • REST, server, and MCP integration

Project Samples

Project Activity

See All Activity >

Categories

Software Testing

License

MIT License

Follow DALFOX

DALFOX Web Site

Other Useful Business Software
MongoDB Atlas runs apps anywhere Icon
MongoDB Atlas runs apps anywhere

Deploy in 115+ regions with the modern database for every enterprise.

MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of DALFOX!

Additional Project Details

Operating Systems

Linux, Mac

Programming Language

Rust

Related Categories

Rust Software Testing Tool

Registered

14 hours ago