| 10103 |
Image Exposes Location or Privacy Data |
beta |
Informational |
Passive |
| 100002 |
Server is running on Clacks - GNU Terry Pratchett |
alpha |
Informational |
Script Passive |
| 100004 |
Content Security Policy Violations Reporting Enabled |
alpha |
Informational |
Script Passive |
| 100012 |
Information Disclosure - IBAN Numbers |
alpha |
Low |
Script Passive |
| 100013 |
Information Disclosure - Private IP Address |
alpha |
Medium |
Script Passive |
| 100019 |
Information Disclosure - Server Header |
alpha |
Low |
Script Passive |
| 100023 |
Information Disclosure - X-Powered-By Header |
alpha |
Low |
Script Passive |
| 100034 |
Information Disclosure - Google API Key |
alpha |
Informational |
Script Passive |
| 100036 |
Information Disclosure - Amazon S3 Bucket URL |
alpha |
Low |
Script Passive |
| 200006-1 |
Credit Card Number |
alpha |
Low |
Tool |
| 200006-2 |
Social Security Number |
alpha |
Low |
Tool |
| 200009-1 |
JavaScript includes sourceMappingURL |
alpha |
Low |
Tool |
| 200009-2 |
HTML references .map files |
alpha |
Low |
Tool |
| 200009-3 |
Webpack dev-server / hot reload artifacts |
alpha |
Low |
Tool |
| 200009-4 |
Next.js build metadata exposed |
alpha |
Low |
Tool |
| 200011-1 |
Private key material exposed |
alpha |
Low |
Tool |
| 200011-2 |
AWS Access Key ID pattern |
alpha |
Low |
Tool |
| 200011-3 |
Slack token pattern |
alpha |
Low |
Tool |
| 200011-4 |
GitHub token pattern |
alpha |
Low |
Tool |
| 200011-5 |
Sentry DSN exposed |
alpha |
Low |
Tool |
| 200011-6 |
Firebase config exposed |
alpha |
Low |
Tool |
| 200011-7 |
Stripe publishable key exposed |
alpha |
Low |
Tool |
| 200011-8 |
Mapbox token exposed |
alpha |
Low |
Tool |
| 200011-9 |
Google API key pattern |
alpha |
Low |
Tool |
| 200012-1 |
Swagger UI detected |
alpha |
Informational |
Tool |
| 200012-2 |
OpenAPI spec detected |
alpha |
Informational |
Tool |
| 200012-3 |
API docs endpoint observed |
alpha |
Informational |
Tool |
| 200012-4 |
GraphQL endpoint observed |
alpha |
Informational |
Tool |
| 200012-5 |
GraphiQL / GraphQL Playground detected |
alpha |
Informational |
Tool |
| 200013-1 |
security.txt observed |
alpha |
Informational |
Tool |
| 200013-2 |
OIDC well-known configuration observed |
alpha |
Informational |
Tool |
| 200013-3 |
Android assetlinks.json observed |
alpha |
Informational |
Tool |
| 200013-4 |
Apple app-site-association observed |
alpha |
Informational |
Tool |
| 200016-1 |
Internal IP address leaked in response |
alpha |
Low |
Tool |
| 200016-2 |
localhost/127.0.0.1 referenced in response |
alpha |
Low |
Tool |
| 200016-3 |
Environment hints (dev/staging/test) in response |
alpha |
Low |
Tool |
| 200016-4 |
Cloud metadata IP referenced |
alpha |
Low |
Tool |
| 200019-1 |
Admin/management path observed |
alpha |
Informational |
Tool |
| 200019-2 |
Debug/diagnostic path observed |
alpha |
Informational |
Tool |
| 200019-3 |
Spring Boot actuator endpoint observed |
alpha |
Informational |
Tool |
| 200019-4 |
Swagger/OpenAPI path observed |
alpha |
Informational |
Tool |
| 200019-5 |
GraphQL path observed |
alpha |
Informational |
Tool |
| 200019-6 |
Potential backup file observed |
alpha |
Informational |
Tool |
| 200019-7 |
Environment/config file observed |
alpha |
Informational |
Tool |
| 200019-8 |
Potential .git exposure path observed |
alpha |
Informational |
Tool |
| 200019-9 |
phpinfo endpoint observed |
alpha |
Informational |
Tool |