#xss
Live, measured metrics for the hashtag #xss from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #xss
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · fosstodon.org (Mastodon public tags API) · fetched 2026-07-27 08:08 UTC5 uses by 5 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · fosstodon.org (Mastodon public search API) · fetched 2026-07-27 08:08 UTCLive pulse
measured · fosstodon.org (Mastodon tag timeline) · fetched 2026-07-27 08:08 UTCEverything below is measured over the latest 40 public posts (spanning ~1738 hours).
Posting hours (UTC) — busiest: 08:00
Languages: English (19) · German (11) · Russian (4) · Italian (3) · Polish (2) · Spanish (1)
Avg boosts / post: 2
Top of the latest posts
#widentity ist ein digital identity provider, der ein geschäftliches Interesse an einem Internet hat, das möglichst wenig anonym ist. Nebenbei basteln sie an #wsocial, um Identitäten einzusammeln https://t1p.de/widentity (lol) #xss #rofl
⚠️ A jQuery 3.5.1 finding isn't always a vulnerability. 🔍 Learn how to separate scanner noise from real XSS risk by verifying runtime versions, plugins, and unsafe DOM patterns. 👉 https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabi
🔍 Iframes aren't the problem. Blind trust between frames is. Learn how attackers abuse postMessage, weak sandboxing, and embedded content flows. 👉 https://7asecurity.com/blog/2026/06/iframe-xss-security/ #AppSec #WebSecurity #XSS
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/xss