pkg.sopackage field notes

brew / rank 2903

Install dalfox with Homebrew

XSS scanner and utility focused on automation. Version 3.1.2 via Homebrew; verified 2026-08-02.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install dalfox

provider-native install command

overview

Package summary

XSS scanner and utility focused on automation

Commands and aliases

  • dalfox

history

Project history and usage

Dalfox is an open-source XSS scanner and security automation CLI built around parameter discovery, context-aware payload generation, and verified reporting formats useful in bug bounty and DevSecOps workflows.

Project history

The project identifies itself as Dalfox, combining the Korean word for moon with 'Fox', and its older Go-era README described it as a successor-style rewrite after XSpear. Current official documentation presents v3 as a Rust rewrite while preserving the Go v2 branch for security backports.

Adoption history

Dalfox became package-manager friendly because it ships as a single CLI and documents installation through Homebrew, Snap, Nix, cargo, Arch AUR, prebuilt binaries, and source builds. Its official pages emphasize fitting into existing recon stacks instead of requiring a heavy scanner platform.

How it is used

Typical use is to scan a single URL, a file of URLs, raw HTTP input, or piped crawler output, then export findings as plain text, JSON, JSONL, Markdown, SARIF, TOML, or through REST and MCP server modes.

Why package nerds care

For package maintainers, Dalfox is a modern security CLI with a clean single-binary distribution story and a visible language/runtime transition from Go v2 to Rust v3, making it a useful example of how security tools move across ecosystems while keeping package channels alive.

Timeline

  • 2020: Go module metadata records a stable v1-era Dalfox release.
  • 2025: Official release notes documented expanded server, report, and raw request workflow support in the v2 line.
  • 2026: Official docs present Dalfox v3.1.2 and a Rust-based v3 line.

Related projects

  • Dalfox's own history points back to XSpear as prior XSS tooling by the same author, and its package ecosystem sits beside proxy/recon tools such as Caido, Burp-style raw request workflows, and CI code-scanning consumers of SARIF.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for dalfox. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
$XDG_CONFIG_HOME/dalfox/config.toml~/.config/dalfox/config.toml

executables

Installed executables

CommandKindExposureNote
dalfoxexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version3.1.2
manager updated2026-08-02
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:dalfox
Version3.1.2
Package managerHomebrew
Homepagehttps://dalfox.hahwul.com
Repositoryhttps://github.com/hahwul/dalfox
Last updated2026-08-02T11:57:54Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation