# API Reference: Testing for XSS Vulnerabilities with Burp Suite ## Burp Suite Professional Components ### Scanner - Active scan: Automatically tests parameters for XSS - Passive scan: Identifies reflected inputs and missing security headers - Scan configuration: XSS-focused audit checks ### Repeater - Send individual requests for manual payload testing - Compare request/response pairs across payload variations - Test character encoding behavior ### Intruder - Positions: Mark injectable parameters - Payloads: Load XSS wordlists - Grep-Match: Flag responses containing `alert(`, `onerror=`, `