QuickXSS
Automate XSS discovery by chaining waybackurls, gau, gf, and dalfox.
Quick Start
pip install quickxss
quickxss setup --install # Auto-install gf, dalfox, waybackurls, gau
quickxss scan -d testphp.vulnweb.com
Installation
pip install quickxss
Or with pipx:
pipx install quickxss
Usage
quickxss scan -d testphp.vulnweb.com # Basic scan
quickxss scan -d testphp.vulnweb.com -b blind.xss.ht # With blind XSS callback
quickxss scan -d testphp.vulnweb.com -o results.txt # Custom output name
quickxss setup # Check dependencies
quickxss setup --install # Auto-install missing deps
Docker
docker build -t quickxss .
docker run --rm -it quickxss scan -d testphp.vulnweb.com
Output
Results saved to results/<domain>/:
| File | Description |
|---|---|
<domain>.txt |
Raw URL collection |
<domain>_xss.txt |
Candidate URLs for testing |
results.txt |
Dalfox findings |
Development
pytest # Run tests
QUICKXSS_INTEGRATION=1 pytest -m integration # Integration tests
make isort # Sort imports
make lint # Run linter
License
Release files for quickxss 3.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| quickxss-3.0.1.tar.gz | 15.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| quickxss-3.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.7 kB
Release files / quickxss-3.0.1.tar.gz
| Download URL | quickxss-3.0.1.tar.gz |
|---|---|
| Size | 15.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
61834caaec47a8314dc37ab250c53d7df7ea8e1d12e2b2f3fd049f33b43935bf
|
|
BLAKE2b-256 checksum How to use checksums |
6671c3b92a15cb901f5f59b6c4d43858467d432eaafd8bcdcd1cab0d891d7f6a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 27, 2026.
Transparency logRelease files / quickxss-3.0.1-py3-none-any.whl
| Download URL | quickxss-3.0.1-py3-none-any.whl |
|---|---|
| Size | 20.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
51c27d4a5b73a7176b09bcd3afb0c908814cd8474799c7a22d62d1f54814cf64
|
|
BLAKE2b-256 checksum How to use checksums |
54fa4875310ef41745ea0a4a299f8b9435623746b3d725f92c1a12d3415030ec
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 27, 2026.
Transparency log