Rails ERB XSS check — find unsafe output in templates

Finds unescaped output in Rails ERB templates - raw, html_safe, <%==, script and href context - and names the escaping helper that fixes each line. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Open full tool → getreadystack.com