juice-shop/juice-shop

View on GitHub
.zap/rules.tsv

Summary

Maintainability
Test Coverage
10109    IGNORE    (Modern Web Application)
10035    IGNORE    (Strict-Transport-Security Header Not Set)
10098    IGNORE    (Cross-Domain Misconfiguration)
10017    IGNORE    (Cross-Domain JavaScript Source File Inclusion)
10096    IGNORE    (Timestamp Disclosure - Unix)
10015    IGNORE    (Incomplete or No Cache-control and Pragma HTTP Header Set)
10038    IGNORE    (Content Security Policy (CSP) Header Not Set)
10099    IGNORE    (Source Code Disclosure - Java)
10027    IGNORE    (Information Disclosure - Suspicious Comments)
10094    IGNORE    (Base64 Disclosure)
10063    IGNORE    (Feature Policy Header Not Set)
10049    IGNORE    (Storable but Non-Cacheable Content)
10049    IGNORE    (Non-Storable Content)
10110    IGNORE    (Dangerous JS Functions)
90004    IGNORE    (Insufficient Site Isolation Against Spectre Vulnerability)
90005    IGNORE    (Sec-Fetch-Dest Header is Missing)
90005    IGNORE    (Sec-Fetch-Mode Header is Missing)
90005    IGNORE    (Sec-Fetch-Site Header is Missing)
90005    IGNORE    (Sec-Fetch-User Header is Missing)