Cross-site scripting ruleset

clearplane-xss detects script markup, event handlers, dangerous URI schemes and related browser injection patterns in selected request fields. Detection depends on the supplied field and document context; it is not a browser execution or output-encoding check.

Paranoia levels and compatibility

Rich-text editors, HTML examples and code uploads can match at level 1. Level 2 adds stricter patterns, including bounded checks for script markup, legacy HTML data binding, remote HTML imports and split JavaScript schemes when an XML body cannot be parsed completely. Review the coverage report and use narrowly scoped target exclusions for trusted authoring fields.

Start in Detection, review detections, and configure only the exclusions needed for the affected route and field.

See the measured coverage for the exact tested payload hashes, missed detections and false-positive rates. Ruleset operation explains activation, stages and rollback.