Find XSS
that scanners miss.

POKEXSS is a modern cross-site scripting scanner built for bug hunters and red teams. Reflected, DOM, and blind — with WAF fingerprinting and a payload arsenal that knows the modern web.

Reflected DOM Blind / OOB WAF bypass Form auto-discovery

Built for finding real bugs

Not a CVE feed dressed up as a scanner — POKEXSS focuses on the single bug class it cares about, and goes deeper there than anything else.

❯_

Reflected XSS

Per-parameter probing with 50+ base payloads and 30+ mutation strategies — tag-case shuffling, attribute breakouts, JS-context escapes, comment smuggling.

DOM XSS

Headless Chromium with hooked sinks (innerHTML, document.write, eval, setTimeout, Function) traces taint from source to sink, then proves exploitability.

Blind XSS

Out-of-band beacons fire on stored-and-rendered injections in admin panels, support tickets, log viewers — anywhere a payload lands but doesn’t reflect immediately.

WAF detection & bypass

Fingerprints 20+ WAFs, then routes payloads through bypass-aware mutators — null bytes, case-folding, CR/LF/FF whitespace tricks, entity smuggling, double-nest tags.

Form auto-discovery

Crawls the page for forms, extracts every input, and submits each one with payloads through the right method (GET/POST) and content type.

🔐

Privacy by design

Scan results live in memory only and auto-expire after one hour. Hit the “forget” button and they’re gone immediately. Your POCs are yours.

Pricing

Pick the cadence that matches your workload. All paid plans unlock every scan mode, WAF bypass, form auto-discovery, and the full payload library.

Monthly Classic

per month (recurring)
$7
Special Offer
  • POKEXSS Web UI
  • All scan modes (Reflected, DOM, Blind)
  • WAF detection + bypass
  • Form auto-discovery
  • Up to 100 scans/day

1-Month

per 1 month (billed once)
$19
Regular Price
  • POKEXSS Web UI + API
  • All scan modes
  • WAF detection + bypass
  • Form auto-discovery
  • Up to 5k API calls/day

3-Months

per 3 months (billed once)
$49
Regular Price
  • POKEXSS Web UI + API
  • All scan modes
  • WAF detection + bypass
  • Form auto-discovery
  • Up to 5k API calls/day

6-Months

per 6 months (billed once)
$79
Regular Price
  • POKEXSS Web UI + API
  • All scan modes
  • WAF detection + bypass
  • Form auto-discovery
  • Up to 5k API calls/day
i
How redemption works. After you complete payment we email you a license key. Sign in and paste the key on your account page — your tier unlocks immediately. No subscriptions to cancel, no card stored on our side.