Safe Literal Text

Exact Literal Character Sequence Retained

The template delimiters are preserved as verbatim string content without server-side mathematical execution.

Active Inspected Body Text
{{7*7}}
Rendered String Length: 7 chars SSTI Mathematical Verdict: Un-evaluated (Not 49)
Template Engine Syntax Detection Matrix 3 Engines Match Delimiters
Engine Ecosystem Delimiter Syntax Simulated Output Security Significance
Why {{7*7}} is the universal SSTI benchmark: In server-side template injection fuzzing, mathematical multiplication (like 7*7) is universally used because plain text renders literally as {{7*7}}, whereas an active vulnerable template interpreter will parse the AST, evaluate the multiplication operator, and emit the product 49.
Ready: Payload inspection active.
About Server-Side Template Injection (SSTI) & Expression Syntax

Server-Side Template Injection occurs when user-supplied input is embedded directly into a template document and parsed by an evaluation engine rather than passed as a data parameter. Attackers exploit SSTI to inspect server environment variables, read arbitrary local files, and achieve Remote Code Execution (RCE).

Standard detection begins with mathematical injection probes such as {{7*7}}, ${7*7}, or <%= 7*7 %>. If the rendered response contains 49 rather than the literal braces, the input boundary has crossed into server template parsing.

Evaluating Template Delimiters and SSTI Probes

Read the explanation

Template engines detect special delimiters like double curly braces or dollar signs in user input to distinguish static text from executable expressions. In safe mode, the application treats the input as an inert literal string, preserving delimiters intact and preventing arithmetic execution. Selecting SSTI Vulnerable mode routes the payload through template parsing. The arithmetic expression evaluates to 49, exposing an injection vulnerability.

Enjoy this tool? Build your own with Super