- Site: http://localhost:3004
New Alerts
- Absence of Anti-CSRF Tokens [10202] total: 2:
- Content Security Policy (CSP) Header Not Set [10038] total: 2:
- Cookie No HttpOnly Flag [10010] total: 11:
- Cookie without SameSite Attribute [10054] total: 10:
- Dangerous JS Functions [10110] total: 1:
- Full Path Disclosure [110009] total: 2:
- Permissions Policy Header Not Set [10063] total: 11:
- Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) [10037] total: 3:
- Timestamp Disclosure - Unix [10096] total: 4:
- Base64 Disclosure [10094] total: 7:
- Information Disclosure - Suspicious Comments [10027] total: 14:
- Loosely Scoped Cookie [90033] total: 12:
- Modern Web Application [10109] total: 3:
- Non-Storable Content [10049] total: 3:
- Sec-Fetch-Dest Header is Missing [90005] total: 3:
- Sec-Fetch-Mode Header is Missing [90005] total: 3:
- Sec-Fetch-Site Header is Missing [90005] total: 3:
- Sec-Fetch-User Header is Missing [90005] total: 3:
- Session Management Response Identified [10112] total: 10:
- Storable and Cacheable Content [10049] total: 4:
- Storable but Non-Cacheable Content [10049] total: 4:
View the following link to download the report.
RunnerID:10290409709
ZAP is supported by the Crash Override Open Source Fellowship
New Alerts
View the following link to download the report.
RunnerID:10290409709
ZAP is supported by the Crash Override Open Source Fellowship