Skip to content

v0.2.1

Choose a tag to compare

@akha-security akha-security released this 23 Sep 12:12
· 18 commits to main since this release

Fixed

  • Reject SQL injection evidence when baseline or payload responses return HTTP 4xx, preventing bad-request boolean probes such as 1 AND 20909=20909 from being reported as confirmed injection.
  • Continue crawler discovery through browser-assisted rendering when initial HTTP requests are blocked or empty, including 403 responses that still load in a normal browser.
  • Remove crawler route-saturation caps from unbounded full scans and fix queue-drain accounting so discovery does not end while requests are still being scheduled.
  • Initialize adaptive module budgets from the module catalog so every registered full-scan module receives a request plan and usage counter.

Added

  • Coverage-gap reporting for blocked or contentless crawl starts, making 0 crawler requests style failures visible instead of silently completing.
  • Regression tests for blocked-browser crawling, redirect discovery, SQLi 4xx false-positive rejection and catalog-wide module budget initialization.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./....