Socket
Socket
Sign inDemoInstall

xss-test

Package Overview
Dependencies
0
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

    xss-test

xss-test


Version published
Weekly downloads
3
Maintainers
1
Created
Weekly downloads
 

Readme

Source

xss-test

NPM version build status Test coverage Gittip David deps node version npm download

A brief slogan.

foo/xss'"&#

xss link


A thrilling description, it should let me know clearly:

  1. What can it do (and what cannot do)?
  2. Why is it my best choice?

Features

  • List core freatures here.
  • The less the better.
  • Make sure not more than 5.

Requirement

If your project must run in a paticular enviroment.

e.g.

node >= 0.11.14

or

  • IE6~10 ×
  • IE11 √
  • chrome √

Installation

How to install or download the project, show the installation steps or download links.

$ npm install xss-test

Quick start

A carefully prepared demo is indispensable!

It should:

  • Always works (believe me, it is not easy).
  • Easy to run, typically with default config.
  • Demostrate the core features.
  • Use code snippet, screenshot and video when necessary.
var xss-test = require('xss-test');

xss-test.foo(function (err) {

});

Cli options / Configs

-o, --option

Option description.

Default: default value

Give a code snippet if it's hard to understand

Subcommand(e.g. totoro config)

Subcommand description.

-s, --suboption

Suboption description.

Default: default value

API Reference

Class(config)

Class description.

  • config: description.
  • config.property: description.
Code snippet here
#classProperty

Property description.

#classMethod(param1, param2)

Method description.

  • param1: description.
  • param2: description.
Code snippet here
.objectProperty

Property description.

.objectMethod(param1, param2)

Method description.

  • param1: description.
  • param2: description.
Code snippet here

Contributing

Plain text or a link both be OK.

License

MIT


xss markdown

come from https://github.com/markdown-it/markdown-it/blob/master/test/fixtures/markdown-it/xss.txt

. normal link .

normal link

.

Should not allow some protocols in links and images

. xss link

xss link

xss link

xss link

xss link .

[xss link](javascript:alert(1))

[xss link](JAVASCRIPT:alert(1))

[xss link](vbscript:alert(1))

[xss link](VBSCRIPT:alert(1))

[xss link](file:///123)

.

. xss link .

xss link

.

. xss link .

[xss link](<javascript:alert(1)>)

.

. xss link .

[xss link](javascript:alert(1))

.

Image parser use the same code base.

. xss link .

![xss link](javascript:alert(1))

.

Autolinks

. <javascript:alert(1)>

javascript:alert(1) .

<javascript:alert(1)>

<javascript:alert(1)>

.

Linkifier

. javascript:alert(1)

javascript:alert(1) .

javascript:alert(1)

javascript:alert(1)

.

Keywords

FAQs

Last updated on 05 Jan 2015

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc