Rails ERB XSS check — find unsafe output in templates
Finds unescaped output in Rails ERB templates - raw, html_safe, <%==, script and href context - and names the escaping helper that fixes each line. Runs entirely in your browser — nothing is uploaded.
Free here: Audit the ERB template you have open: every unescaped-output line, with the escaping helper that fixes it.. In the editor: Scan every .erb file in the workspace at once and export a dated Markdown/CSV evidence report you keep. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.