Total KB References
160
Grounded Security Passages
Executable Audit Rules
31 Active
Book-Grounded Scanner Probes
Standards & CWE Catalog
71
OWASP, MITRE, NIST, ISO, RFCs
Cybersecurity Books
65
Books & Ingested PDFs
Audit Target URL & Authenticated Scan Options
Knowledge Base Audit Engine • 160 References & 31 Active Book-Grounded Rules Loaded Click to view dynamic KB rules →
HIGH sql-injection-surface (sqli)
OWASP-A03-INJECTION CWE-89
MEDIUM reflected-xss-surface (xss)
OWASP-A03-INJECTION CWE-79
HIGH strict-transport-security (header_required)
OWASP-SEC-HEADERS CWE-319
HIGH content-security-policy (header_required)
OWASP-SEC-HEADERS CWE-79
LOW x-content-type-options (header_required)
OWASP-SEC-HEADERS CWE-16
LOW referrer-policy (header_required)
OWASP-SEC-HEADERS CWE-200
LOW permissions-policy (header_required)
OWASP-SEC-HEADERS CWE-16
LOW cross-origin-opener-policy (header_required)
OWASP-SEC-HEADERS CWE-693
LOW cross-origin-embedder-policy (header_required)
OWASP-SEC-HEADERS CWE-693
LOW cross-origin-resource-policy (header_required)
OWASP-SEC-HEADERS CWE-693
LOW cache-control (header_required)
OWASP-SEC-HEADERS CWE-524
MEDIUM content-type (header_required)
OWASP-SEC-HEADERS CWE-436
MEDIUM x-frame-options (header_required)
OWASP-CLICKJACK CWE-1021
HIGH Secure (cookie_flag)
OWASP-SESSION CWE-614
HIGH HttpOnly (cookie_flag)
OWASP-SESSION CWE-1004
MEDIUM SameSite (cookie_flag)
OWASP-SESSION CWE-1275
MEDIUM CWE-601 (open_redirect)
CWE-601 CWE-601
HIGH CWE-200-SENSITIVE (sensitive_paths)
CWE-200-SENSITIVE CWE-200
MEDIUM CWE-749 (http_methods)
CWE-749 CWE-749
LOW ddos-mitigation-posture (ddos_mitigation)
ATTACK-T1498-DOS CWE-400
HIGH sql-injection (sqli)
WSTG-INPV-05-SQLI CWE-89
HIGH blind-sqli-surface (blind_sqli)
WSTG-INPV-05-SQLI CWE-89
MEDIUM reflected-xss-surface (xss)
WSTG-INPV-01-XSS CWE-79
LOW ddos-mitigation-posture (ddos_mitigation)
OWASP-DOS-CHEATSHEET CWE-400
HIGH Secure (cookie_flag)
WSTG-SESS-04-FIXATION CWE-384
HIGH HttpOnly (cookie_flag)
WSTG-SESS-04-FIXATION CWE-384
LOW brute-force-rate-limit-posture (ddos_mitigation)
OWASP-RATELIMIT-BRUTEFORCE CWE-307
MEDIUM rate-limit-backoff-posture (rate_limiting)
OWASP-RATELIMIT-BRUTEFORCE CWE-307
HIGH path-traversal-lfi-surface (path_traversal)
WSTG-INPV-07-PATHTRAV CWE-22
HIGH state-changing-form-csrf-token (csrf_token)
WSTG-SESS-05-CSRF CWE-352
MEDIUM rate-limit-backoff-posture (rate_limiting)
OWASP-RATELIMIT-DEEP CWE-307
KB Self-Study & Self-Hardening
DOG-FOODING

The auditor reads its own 160 grounded references, audits this app’s own security posture against every executable rule the books teach, applies the missing hardening to vercel.json & webui.py, then re-audits to prove the fix loop.

Security Audit Progress & Grounding Engine

Ready to audit. Enter a target URL above and click Run Security Audit.
0%
1 TLS & Domain Check
2 Security Probes
3 Crawl & Entry Points
4 160 References Grounding
5 Remediation Bundle
100% Safe & Authorized Audit Guarantee • Powered by 160 Security References

Guaranteed 100% safe, non-destructive, read-only probes with zero data modification or harmful payloads. Every security check, explanation, and remediation bundle is strictly grounded in 160 authoritative security standards & curated cybersecurity books (OWASP Top 10s, MITRE CWE Catalog, ASVS v4.0.3, NIST SP 800-53/160, ISO 27001:2022, PCI DSS v4.0, CIS Benchmarks, IETF RFCs).