Privacy Policy (Web App)

1. Collection of Information

XSSR may collect personal and non-personal information when you use the service. Personal information may include your name, email address, and payment information.

2. Use of Information

We use your information for the following purposes:

  • To provide and maintain our service.
  • To notify you about changes to our service.
  • To offer customer support.
  • To detect, prevent, and address technical issues.

3. Security

XSSR employs reasonable measures to protect your information; however, no method of transmission over the internet is 100% secure.

4. Third Parties

We do not share your information with third parties unless required by law.

5. Contact Information

For any questions or concerns related to our terms, user agreement, or privacy policy, please contact us at [email protected].

Privacy Policy (Browser Extensions)

Chrome Extensions and Firefox Add-ons Policy

1. Collection of Information

XSSR does not collect any personal information, such as your IP address, current URL, user agent, or operating system. We are committed to protecting your privacy while you use our service.

2. Use of Information

We only access the "tabs/currentURL" for the purpose of performing scans to identify vulnerabilities

3. Security

XSSR employs reasonable measures to protect your information; however, no method of transmission over the internet is 100% secure.

4. Third Parties

We do not share your information with third parties unless required by law.

5. Contact Information

For any questions or concerns related to our terms, user agreement, or privacy policy, please contact us at [email protected].

Frequently asked questions

Learn more about how XSSR (XSSRush) works, the difference between plans, and how to get started.

XSSR (also known as XSSRush) is an automatic XSS scanner built to detect cross-site scripting vulnerabilities in web applications. It supports multiple scanning methods, including reflected, DOM-based, and parameter-based testing.

XSSR Standard focuses on speed and simplicity, scanning for reflected and POST-based XSS vulnerabilities.

XSSR Pro offers advanced detection, supporting reflected, POST-based, DOM-based, path-based, header-based XSS, and hidden parameter brute forcing for deeper analysis.

Yes. XSSR Standard is completely free to use and includes fast scanning for reflected and POST-based XSS vulnerabilities.

For advanced features such as DOM-based, header-based, path-based, and hidden parameter scanning, you can upgrade to XSSR Pro, our paid version designed for deeper and more complex analysis.

Yes. XSSR stores the URLs you submit and the scan results so you and other users can view past scans and learn from shared findings. However, we do not store or process any private or sensitive data. All submitted data and results are publicly accessible, making XSSR a transparent and community-driven scanning platform.

Absolutely. You can upgrade to XSSR Pro at any time to unlock all advanced scanning modules and premium features. Your account data and past scans from XSSR Standard will remain available after upgrading.

Don't Just Take Our Word For It

Companies worldwide trust N45HT with their security research and responsible disclosures.

“Thank you for your kind report!”

UnblockVPN logo
UnblockVPN
VPN service provider

“Your hard work is both appreciated and valued, thank you once again for reporting your findings!”

New Work SE logo
New Work SE
Hamburg, Germany

“Thank you for helping Razer secure its customers' information.”

Razer Inc. logo
Razer Inc.
American-Singaporean multinational corporation and technology company

“We look forward to your continuous support in future.”

Samsung logo
Samsung
South Korean multinational electronics corporation

“The safety of our users is of utmost importance to us, so we thank you for your report and dedication to keeping our eBay community safe.”

eBay logo
eBay
American multinational e-commerce corporation

“Thanks very much for participating in the Alibaba Vulnerability Reward Program!”

Alibaba logo
Alibaba
Chinese multinational technology company

“We are deeply grateful for the security issue you shared with us.”

OLX logo
OLX
Global online marketplace

“Again thank you and we wish you the best of luck with your hunting!”

Vercel logo
Vercel
American cloud application company

“Thank you very much for your report.”

Bandicam logo
Bandicam
Screen recording software company

“Terimakasih atas laporannya, sekali lagi kami ucapkan terimakasih.”

Rumahweb logo
Rumahweb
Indonesian web hosting company

“Kami ucapkan terima kasih atas partisipasi Anda karena telah menemukan Bug yang terdapat di KASKUS.”

KASKUS logo
KASKUS
Indonesian online forum

“Thank you for helping keep xiaomi secure!”

Xiaommi logo
Xiaommi
Chinese multinational corporation and technology company

“Thank you for all your efforts!”

httpstatus.io logo
httpstatus.io
Web debugging tool

“This is very helpful.”

httpstatus.io logo
httpstatus.io
Web debugging tool

“Greetings! Thank you for being part of the security community and for your responsible disclosure of this vulnerability.”

Shutterfly logo
Shutterfly
American photography and image sharing company

“Your effort has been acknowledged on our program page and we hope to have the opportunity to collaborate with you again in the future.”

Toyota logo
Toyota
Japanese multinational automotive manufacturer

“Terima kasih buat bantuannya, DomaiNesians. 😁”

DomaiNesia logo
DomaiNesia
Indonesian web hosting company