Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

xsstracer

Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header

scannerRed Team
Official docs ↗Download ↗

Platforms: Linux · Last verified September 6, 2026

Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header Injection.

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Install on BlackArch with `pacman -S xsstracer` (or add the BlackArch repository to an existing Arch Linux install). See the official BlackArch tool listing and upstream homepage linked above for details.

Commonly preinstalled on

BlackArch

Arch Linux-based distribution with one of the largest pentest tool repositories