In-page control
Focus a field and a hover control appears. Open the payload panel to pick a built-in or custom entry by category—without leaving the page under test.
[ AUTHORIZED TESTING · MV3 ]
Chrome extension for ethical security testing. Off by default per origin. Optional Smart-Injection suggests a payload category from field context—suggestions only, not vulnerability detection.
Enable XSSassin only where you have permission. Hover inject and the in-page panel share your default and random rules from the popup.
Focus a field and a hover control appears. Open the payload panel to pick a built-in or custom entry by category—without leaving the page under test.
Optional heuristics infer a likely category from name, id, type, and page path. Fixed defaults and custom-only random mode still win when you set them.
infer(name, id, type, path) → category | fallback scope // never overrides a fixed default