Use when checking whether a web app reflects or stores input that executes as script in a victim's browser — covers reflected, stored, and DOM XSS plus the output-encoding fix.