What this does
Scans an XML document and lists every entity in it: the five predefined entities and how often each is used, numeric character references with their code points, and entities declared in the DOCTYPE with their values and usage counts. Comments and CDATA sections are ignored.
What it flags
- External entities (
SYSTEMorPUBLIC), which are the basis of XXE attacks when a parser resolves them. - Entities that expand to other entities, the pattern used in "billion laughs" denial-of-service documents.
- Named references with no declaration, which make a document not well-formed, and numeric references to characters XML 1.0 forbids.
Limits
This is a static scan of the text, not a parser: it does not fetch external entities and does not expand anything. Use it to review untrusted XML before handing it to a parser.
Privacy
Everything runs in your browser. Your input is never uploaded, stored, or put in the URL.