Pixy Logo Pixy: XSS and SQLI Scanner for PHP Programs

Web Interface

This service allows you to get a first impression about what Pixy can do. Type some PHP code into the text field provided below (or upload a PHP file), and start an XSS analysis by pushing the "Analyze" button. Our Quick Start section contains a brief explanation of the generated output. More information can be found in our Tutorial.

Currently, this service allows you to scan one PHP file for XSS vulnerabilities. If you want to scan a program that consists of multiple files, or if you want to analyze a program for SQLI vulnerabilities, please use the download version.

The results of your analysis will be available for 30 minutes. After that, they are removed to save server space.

Please note that the web interface is still in its early stages of development. If you encounter bugs or long waiting times, please let us know!

Or upload a PHP file here:

Web Interface VS Download Version

Compared to the download version, the web interface to Pixy has a few limitations. The following table shows the most important differences:

Web Interface Download Version
XSS analysis XSS and SQLI analysis
no include file resolution full include file resolution
execution time limited to 1 minute execution finishes when analysis is completed



International Secure Systems Lab