| Page | Result | Pass | Fail | Ignore | Other |
| BlindSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
| BlindSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
| CommandInjection-LEVEL_1 | PASS  | CommandInjection | SqliteSqli | | LDAPi ContentCache 90028 XContent 90004 |
| CommandInjection-LEVEL_2 | FAIL  | | CommandInjection | | |
| CommandInjection-LEVEL_3 | FAIL  | | CommandInjection | | |
| CommandInjection-LEVEL_4 | FAIL  | | CommandInjection | | |
| CommandInjection-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
| ErrorBasedSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
| ErrorBasedSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
| ErrorBasedSQLInjectionVulnerability-LEVEL_3 | FAIL  | | AdvSqli | | |
| ErrorBasedSQLInjectionVulnerability-LEVEL_4 | FAIL  | | AdvSqli | | |
| Http3xxStatusCodeBasedInjection-LEVEL_1 | FAIL  | | SqliteSqli | | 90028 |
| Http3xxStatusCodeBasedInjection-LEVEL_2 | FAIL  | | OpenRedir | | |
| Http3xxStatusCodeBasedInjection-LEVEL_3 | FAIL  | | OpenRedir | | |
| Http3xxStatusCodeBasedInjection-LEVEL_4 | FAIL  | | OpenRedir | | |
| Http3xxStatusCodeBasedInjection-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
| Http3xxStatusCodeBasedInjection-LEVEL_6 | FAIL  | | SqliteSqli | | 90028 |
| Http3xxStatusCodeBasedInjection-LEVEL_7 | FAIL  | | OpenRedir | | |
| JWTVulnerability-LEVEL_1 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_2 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_3 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_4 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_5 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_6 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_7 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_8 | FAIL  | | JWT | | |
| JWTVulnerability-LEVEL_9 | FAIL  | | SqliteSqli | | 90028 |
| PathTraversal-LEVEL_1 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_10 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_11 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_12 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_2 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_3 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_4 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_5 | FAIL  | | SqliteSqli | | 90028 |
| PathTraversal-LEVEL_6 | FAIL  | | SqliteSqli | | 90028 |
| PathTraversal-LEVEL_7 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_8 | FAIL  | | PathTrav | | |
| PathTraversal-LEVEL_9 | FAIL  | | PathTrav | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_1 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_2 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_3 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_4 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_5 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_6 | FAIL  | | PXSSS | | |
| PersistentXSSInHTMLTagVulnerability-LEVEL_7 | FAIL  | | SqliteSqli | | 90028 |
| PersistentXSSInHTMLTagVulnerability-LEVEL_8 | FAIL  | | SqliteSqli | | 90028 |
| UnionBasedSQLInjectionVulnerability-LEVEL_1 | FAIL  | | AdvSqli | | |
| UnionBasedSQLInjectionVulnerability-LEVEL_2 | FAIL  | | AdvSqli | | |
| UnionBasedSQLInjectionVulnerability-LEVEL_3 | PASS  | SqliteSqli | | | 90028 |
| UnrestrictedFileUpload-LEVEL_1 | FAIL  | | PathTrav RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_2 | FAIL  | | RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_3 | FAIL  | | RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_4 | FAIL  | | RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_5 | FAIL  | | RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_6 | FAIL  | | RXSS PXSSS | | |
| UnrestrictedFileUpload-LEVEL_7 | FAIL  | | SqliteSqli | | 90028 |
| UnrestrictedFileUpload-LEVEL_8 | FAIL  | | SqliteSqli | | 90028 |
| XSSInImgTagAttribute-LEVEL_1 | PASS  | RXSS | SqliteSqli | | DXSS 90028 SrcInc |
| XSSInImgTagAttribute-LEVEL_2 | PASS  | RXSS | SqliteSqli | | DXSS 90028 SrcInc |
| XSSInImgTagAttribute-LEVEL_3 | PASS  | RXSS | | | 90028 SrcInc |
| XSSInImgTagAttribute-LEVEL_4 | PASS  | RXSS | | | LDAPi 90028 SrcInc |
| XSSInImgTagAttribute-LEVEL_5 | PASS  | RXSS | | | 90028 SrcInc |
| XSSInImgTagAttribute-SECURE | FAIL  | | RXSS | | |
| XSSWithHTMLTagInjection-LEVEL_1 | PASS  | RXSS | | | DXSS 90028 SrcInc |
| XSSWithHTMLTagInjection-LEVEL_2 | FAIL  | | SqliteSqli | | 90028 |
| XSSWithHTMLTagInjection-LEVEL_3 | FAIL  | | SqliteSqli | | 90028 |
| XXEVulnerability-LEVEL_1 | FAIL  | | XXE | | |
| XXEVulnerability-LEVEL_2 | FAIL  | | XXE | | |
| XXEVulnerability-LEVEL_3 | FAIL  | | XXE | | |
| Plugin | ms | Reqs | Quality |
| Path Traversal | 0:01:49.969 | 36858 | release |
| Remote File Inclusion | 0:01:12.677 | 29120 | release |
| Source Code Disclosure - /WEB-INF folder | 0:00:00.016 | 0 | release |
| External Redirect | 0:00:24.451 | 4576 | release |
| Server Side Include | 0:00:16.559 | 1664 | release |
| Cross Site Scripting (Reflected) | 0:00:15.081 | 1401 | release |
| Cross Site Scripting (Persistent) - Prime | 0:00:15.414 | 416 | release |
| Cross Site Scripting (Persistent) - Spider | 0:00:05.182 | 129 | release |
| Cross Site Scripting (Persistent) | 0:00:14.822 | 0 | release |
| SQL Injection | 0:01:49.498 | 23410 | release |
| Server Side Code Injection | 0:00:22.712 | 3328 | release |
| Remote OS Command Injection | 0:01:41.047 | 35193 | release |
| Directory Browsing | 0:00:04.268 | 129 | release |
| Buffer Overflow | 0:00:15.837 | 377 | release |
| Format String Error | 0:00:15.939 | 1131 | release |
| CRLF Injection | 0:00:22.241 | 2912 | release |
| Parameter Tampering | 0:00:20.889 | 1844 | release |
| ELMAH Information Leak | 0:00:00.022 | 1 | release |
| .htaccess Information Leak | 0:00:04.450 | 25 | release |
| Script Active Scan Rules | 0:00:00.008 | 0 | release |
| Source Code Disclosure - Git | 0:00:04.165 | 0 | beta |
| Source Code Disclosure - File Inclusion | 0:00:55.591 | 382 | beta |
| Remote Code Execution - Shell Shock | 0:00:15.119 | 832 | beta |
| Httpoxy - Proxy Header Misuse | 0:00:14.510 | 645 | beta |
| Anti-CSRF Tokens Check | 0:00:01.236 | 0 | beta |
| Cross-Domain Misconfiguration | 0:00:00.034 | 2 | beta |
| Heartbleed OpenSSL Vulnerability | 0:00:00.049 | 2 | beta |
| Source Code Disclosure - CVE-2012-1823 | 0:00:04.751 | 103 | beta |
| Remote Code Execution - CVE-2012-1823 | 0:00:11.777 | 258 | beta |
| Session Fixation | 0:00:01.430 | 0 | beta |
| SQL Injection - MySQL | 0:00:45.736 | 9152 | beta |
| SQL Injection - Hypersonic SQL | 0:00:36.300 | 7072 | beta |
| SQL Injection - Oracle | 0:00:33.774 | 5408 | beta |
| SQL Injection - PostgreSQL | 0:00:36.437 | 7072 | beta |
| SQL Injection - SQLite | 0:02:42.094 | 35482 | beta |
| Cross Site Scripting (DOM Based) | 0:13:15.167 | 1673 | beta |
| SQL Injection - MsSQL | 0:00:34.450 | 6386 | beta |
| Advanced SQL Injection | 1:39:25.087 | 1549063 | beta |
| XPath Injection | 0:00:16.408 | 1248 | beta |
| XML External Entity Attack | 0:00:01.478 | 0 | beta |
| Generic Padding Oracle | 0:00:14.912 | 2 | beta |
| Expression Language Injection | 0:00:14.392 | 416 | beta |
| Cloud Metadata Potentially Exposed | 0:00:00.043 | 1 | beta |
| Source Code Disclosure - SVN | 0:00:10.527 | 261 | beta |
| Relative Path Confusion | 0:00:02.491 | 18 | beta |
| Apache Range Header DoS (CVE-2011-3192) | 0:00:04.934 | 145 | beta |
| Backup File Disclosure | 0:01:54.259 | 26639 | beta |
| HTTP Only Site | 0:00:00.103 | 0 | beta |
| Integer Overflow Error | 0:00:20.185 | 1508 | beta |
| Proxy Disclosure | 0:00:03.822 | 129 | beta |
| Trace.axd Information Leak | 0:00:03.795 | 25 | beta |
| .env Information Leak | 0:00:03.632 | 25 | beta |
| Hidden File Finder | 0:00:00.356 | 38 | beta |
| XSLT Injection | 0:00:17.580 | 2896 | beta |
| Insecure HTTP Method | 0:00:33.918 | 1548 | beta |
| HTTPS Content Available via HTTP | 0:00:01.668 | 0 | beta |
| GET for POST | 0:00:01.788 | 0 | beta |
| User Agent Fuzzer | 0:00:32.674 | 903 | beta |
| HTTP Parameter Pollution | 0:00:01.714 | 0 | beta |
| Possible Username Enumeration | 0:00:00.022 | 0 | beta |
| Cookie Slack Detector | 0:00:01.084 | 0 | beta |
| LDAP Injection | 0:02:50.175 | 1135 | alpha |
| NoSQL Injection - MongoDB | 0:00:47.772 | 9296 | alpha |
| Example Active Scan Rule: Denial of Service | 0:00:14.663 | 0 | alpha |
| An example active scan rule which loads data from a file | 0:00:14.613 | 0 | alpha |
| JWT Scan Rule | 0:00:15.126 | 0 | alpha |
| | | |
| Total | 2:19:32 | - | - |