#xss

Live, measured metrics for the hashtag #xss from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.

hashtag.org network · sponsored

Own #xss

This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.

$5,313.74/ year · 3-character #name
Claim #xss$5,313.74/yr
Annual, renews each year
Buy on hashtag.space (web3)
one-timepay once, yours for life
card via hashtag.org · tokens via hashtag.space
5
Uses / 7 days
Mastodon
5
Accounts / 7 days
Mastodon
40
Recent posts
Mastodon
~0/hr
Recent pace
Mastodon · last 40
1.4
Avg reactions / post
Mastodon · last 40

Day-by-day usage

measured · fosstodon.org (Mastodon public tags API) · fetched 2026-07-27 08:08 UTC
2
07-21
1
07-22
0
07-23
1
07-24
0
07-25
0
07-26
1
07-27

5 uses by 5 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.

Related hashtags

measured · fosstodon.org (Mastodon public search API) · fetched 2026-07-27 08:08 UTC

Live pulse

measured · fosstodon.org (Mastodon tag timeline) · fetched 2026-07-27 08:08 UTC

Everything below is measured over the latest 40 public posts (spanning ~1738 hours).

Posting hours (UTC) — busiest: 08:00

00:0012:0023:00

Languages: English (19) · German (11) · Russian (4) · Italian (3) · Polish (2) · Spanish (1)

Avg boosts / post: 2

Top of the latest posts

  • #widentity ist ein digital identity provider, der ein geschäftliches Interesse an einem Internet hat, das möglichst wenig anonym ist. Nebenbei basteln sie an #wsocial, um Identitäten einzusammeln https://t1p.de/widentity (lol) #xss #rofl

    kantorkel@[email protected]52602026-06-17 19:59 UTCView post →
  • ⚠️ A jQuery 3.5.1 finding isn't always a vulnerability. 🔍 Learn how to separate scanner noise from real XSS risk by verifying runtime versions, plugins, and unsafe DOM patterns. 👉 https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabi

    7ASecurity@7ASecurity102026-07-21 12:20 UTCView post →
  • 🔍 Iframes aren't the problem. Blind trust between frames is. Learn how attackers abuse postMessage, weak sandboxing, and embedded content flows. 👉 https://7asecurity.com/blog/2026/06/iframe-xss-security/ #AppSec #WebSecurity #XSS

    7ASecurity@7ASecurity102026-06-24 12:25 UTCView post →

Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/xss