XSS Payload Generator
Generate common XSS test payloads by category, with HTML/URL encoding options, for authorized security testing.
🔒 Fully secure. No payloads are executed. Educational purposes only.
Preview (Text Only)
About this tool
This tool provides a categorized library of well-known XSS payload patterns — basic alert boxes, image and SVG event-handler injections, meta-refresh redirects, encoded variants, and more — so security testers don't have to memorize or retype them during an assessment.
Select a payload type or type a custom script snippet, optionally apply HTML encoding, URL encoding, or double encoding, and copy the result for use in your authorized testing workflow.
Responsible use
No payload on this page executes automatically — everything is generated as inert text. This tool is intended strictly for authorized penetration testing, bug bounty work, and security education; only test applications and systems you own or have explicit permission to assess.
