I usually use special tools (like scanners) to test Reflected Cross Site Scripting automatically. Is manually testing against XXS also a good practice?
As long as you are able to validate all the input data and also make sure that only the allowlisted data is allowed you are good to go.
Are you sure you want to hide this comment? It will become hidden in your post, but will still be visible via the comment's permalink.
Hide child comments as well
Confirm
For further actions, you may consider blocking this person and/or reporting abuse
We're a place where coders share, stay up-to-date and grow their careers.
I usually use special tools (like scanners) to test Reflected Cross Site Scripting automatically. Is manually testing against XXS also a good practice?
As long as you are able to validate all the input data and also make sure that only the allowlisted data is allowed you are good to go.