A real report, not a mockup

These are the exact findings the scanner produces for a deliberately broken target — the same rows a test re-derives and compares on every build, so this page cannot drift into a description of itself.

13 findings · 1 critical · 2 high · 4 medium · 4 low · 2 info · 4 proven (the weakness itself is in a response the scan holds)

FindingSeverityWeaknessHow we knowConfidenceFix-first
환경설정 파일 노출 (.env)
Exposed Files
criticalCWE-538proven · theoretical80%60
Reflected XSS via `q`
Cross-Site Scripting
highCWE-79proven · active92%74
Cookie missing Secure and HttpOnly (sid)
Session
highCWE-614inferred · poc82%60
Open redirect via `url`
Insecure Configuration
mediumCWE-601proven · active92%48
Missing Content-Security-Policy
HTTP Headers
mediumCWE-693inferred · theoretical90%31
Missing HSTS header
HTTP Headers
mediumCWE-319inferred · theoretical90%31
디렉터리 목록 노출
Exposed Files
mediumCWE-548proven · theoretical65%28
Version disclosure: Apache 2.4.49 (Unix)
Information Disclosure
lowCWE-200inferred · poc84%21
Version disclosure: PHP 7.4.3
Information Disclosure
lowCWE-200inferred · poc84%21
Missing X-Content-Type-Options
HTTP Headers
lowCWE-430inferred · theoretical90%16
Missing X-Frame-Options / frame-ancestors
HTTP Headers
lowCWE-1021inferred · theoretical90%16
Missing Permissions-Policy
HTTP Headers
infoinferred · theoretical90%5
Missing Referrer-Policy
HTTP Headers
infoinferred · theoretical90%5

What the columns mean

Generated from packages/scan-engine/src/regression-corpus.json. Changing what the scanner says changes this page, and a test fails if the two disagree.

Sample report — heimdallX