Transparent by design
One weakness at a time.
Coverage follows OWASP Top 10:2025. No claim of complete OWASP coverage.
Experimental · see validation reportA01 / Broken Access Control
CWE-639 — Authorization Bypass Through User-Controlled Key
Authenticated horizontal access checks using observed object references, safe retrieval requests, explicit denial evidence, and private-data exposure. Public or shared data and ambiguous ownership remain inconclusive.
Requires a verified target and working test credentials. Source correlation requires a connected repository; deployed revision matching is not assumed.
Verification replays saved foreign requests and legitimate controls. Discovery is bounded and cannot cover every custom workflow, SSO, MFA, or API schema.
A02 Security MisconfigurationRoadmap · not executed
A03 Software Supply Chain FailuresRoadmap · not executed
A04 Cryptographic FailuresRoadmap · not executed
A05 InjectionRoadmap · not executed
A06 Insecure DesignRoadmap · not executed
A07 Authentication FailuresRoadmap · not executed
A08 Software or Data Integrity FailuresRoadmap · not executed
A09 Security Logging and Alerting FailuresRoadmap · not executed
A10 Mishandling of Exceptional ConditionsRoadmap · not executed
“No issue observed” applies only to executed checks. It is not a certification that your application is secure.