SiteShadow

Docs

Vulnerability library

A plain-language index of the vulnerability categories SiteShadow is designed to surface in code. This list grows over time and does not imply complete coverage of any standard.

Browse

If you’re new here, start with the OWASP Top 10. The rest is a deeper set of categories and checks.

OWASP Top 10 (A01–A11)
Core categories (auth, secrets, config, API safety)
Heuristic analysis (H01–H14)
Quality & process checks (QP)
Secure Coding Practices (SCP)

CWE spotlights

These links point to the current markdown entries that ship with the site.

Always validate findings in context and prefer the lowest-risk fix that preserves intent.