Starter OWASP coverage
OWASP Starter extends the baseline with checks for permissive CORS policies, open redirects, directory listings, and exposed sensitive files.
The scanner keeps requests scoped to verified domains and uses safe probes designed for recurring production checks.
Built for remediation
Findings are grouped by severity and include the affected URL, evidence, and fix guidance so engineering teams can prioritize without guesswork.
Historical reports help show whether recurring risks are improving or returning across releases.
All 14 checks in this package
Included from the Developer plan and up.
- CORS Policy
- CORS Edge Cases (null origin / preflight)
- Open Redirect
- Directory Listing
- Sensitive Files
- Secrets in JavaScript Bundles
- CSP Quality Review
- Trusted Types Signal
- Source Map Exposure
- Deprecated Browser APIs
- Harmless Reflected XSS Indicators
- Safe SQL Injection Indicators
- SSTI Template Injection Indicator
- Error Disclosure Expansion