Total KB References
160
Grounded Security Passages
Executable Audit Rules
31 Active
Book-Grounded Scanner Probes
Standards & CWE Catalog
71
OWASP, MITRE, NIST, ISO, RFCs
Cybersecurity Books
65
Books & Ingested PDFs
Audit Target URL & Authenticated Scan Options
Knowledge Base Audit Engine • 160 References & 31 Active Book-Grounded Rules Loaded Click to view dynamic KB rules →
HIGH
sql-injection-surface
(sqli)
OWASP-A03-INJECTION
CWE-89
MEDIUM
reflected-xss-surface
(xss)
OWASP-A03-INJECTION
CWE-79
HIGH
strict-transport-security
(header_required)
OWASP-SEC-HEADERS
CWE-319
HIGH
content-security-policy
(header_required)
OWASP-SEC-HEADERS
CWE-79
LOW
x-content-type-options
(header_required)
OWASP-SEC-HEADERS
CWE-16
LOW
referrer-policy
(header_required)
OWASP-SEC-HEADERS
CWE-200
LOW
permissions-policy
(header_required)
OWASP-SEC-HEADERS
CWE-16
LOW
cross-origin-opener-policy
(header_required)
OWASP-SEC-HEADERS
CWE-693
LOW
cross-origin-embedder-policy
(header_required)
OWASP-SEC-HEADERS
CWE-693
LOW
cross-origin-resource-policy
(header_required)
OWASP-SEC-HEADERS
CWE-693
LOW
cache-control
(header_required)
OWASP-SEC-HEADERS
CWE-524
MEDIUM
content-type
(header_required)
OWASP-SEC-HEADERS
CWE-436
MEDIUM
x-frame-options
(header_required)
OWASP-CLICKJACK
CWE-1021
HIGH
Secure
(cookie_flag)
OWASP-SESSION
CWE-614
HIGH
HttpOnly
(cookie_flag)
OWASP-SESSION
CWE-1004
MEDIUM
SameSite
(cookie_flag)
OWASP-SESSION
CWE-1275
MEDIUM
CWE-601
(open_redirect)
CWE-601
CWE-601
HIGH
CWE-200-SENSITIVE
(sensitive_paths)
CWE-200-SENSITIVE
CWE-200
MEDIUM
CWE-749
(http_methods)
CWE-749
CWE-749
LOW
ddos-mitigation-posture
(ddos_mitigation)
ATTACK-T1498-DOS
CWE-400
HIGH
sql-injection
(sqli)
WSTG-INPV-05-SQLI
CWE-89
HIGH
blind-sqli-surface
(blind_sqli)
WSTG-INPV-05-SQLI
CWE-89
MEDIUM
reflected-xss-surface
(xss)
WSTG-INPV-01-XSS
CWE-79
LOW
ddos-mitigation-posture
(ddos_mitigation)
OWASP-DOS-CHEATSHEET
CWE-400
HIGH
Secure
(cookie_flag)
WSTG-SESS-04-FIXATION
CWE-384
HIGH
HttpOnly
(cookie_flag)
WSTG-SESS-04-FIXATION
CWE-384
LOW
brute-force-rate-limit-posture
(ddos_mitigation)
OWASP-RATELIMIT-BRUTEFORCE
CWE-307
MEDIUM
rate-limit-backoff-posture
(rate_limiting)
OWASP-RATELIMIT-BRUTEFORCE
CWE-307
HIGH
path-traversal-lfi-surface
(path_traversal)
WSTG-INPV-07-PATHTRAV
CWE-22
HIGH
state-changing-form-csrf-token
(csrf_token)
WSTG-SESS-05-CSRF
CWE-352
MEDIUM
rate-limit-backoff-posture
(rate_limiting)
OWASP-RATELIMIT-DEEP
CWE-307
KB Self-Study & Self-Hardening
DOG-FOODING
The auditor reads its own 160 grounded references, audits this app’s own security posture against
every executable rule the books teach, applies the missing hardening to vercel.json & webui.py,
then re-audits to prove the fix loop.
Security Audit Progress & Grounding Engine
Ready to audit. Enter a target URL above and click Run Security Audit.
0%
1 TLS & Domain Check
2 Security Probes
3 Crawl & Entry Points
4 160 References Grounding
5 Remediation Bundle
100% Safe & Authorized Audit Guarantee • Powered by 160 Security References
Guaranteed 100% safe, non-destructive, read-only probes with zero data modification or harmful payloads. Every security check, explanation, and remediation bundle is strictly grounded in 160 authoritative security standards & curated cybersecurity books (OWASP Top 10s, MITRE CWE Catalog, ASVS v4.0.3, NIST SP 800-53/160, ISO 27001:2022, PCI DSS v4.0, CIS Benchmarks, IETF RFCs).