xsstracer
Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header
Platforms: Linux · Last verified September 6, 2026
Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header Injection.
Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.
Getting started
Install on BlackArch with `pacman -S xsstracer` (or add the BlackArch repository to an existing Arch Linux install). See the official BlackArch tool listing and upstream homepage linked above for details.
