Tested this script against wavsep, the web application vuln scanner benchmarking tool. It fails multiple XSS tests of wavsep but most of the problems all seem to lie in the logic for determining whether it's the single or double quote that's the delimiting quote. In the coming update, xsscrapy should cut the amount of requests it makes in half and have significantly better detection rates. May take a few weeks or more to accomplish.
Tested this script against wavsep, the web application vuln scanner benchmarking tool. It fails multiple XSS tests of wavsep but most of the problems all seem to lie in the logic for determining whether it's the single or double quote that's the delimiting quote. In the coming update, xsscrapy should cut the amount of requests it makes in half and have significantly better detection rates. May take a few weeks or more to accomplish.