Skip to content

v0.2.2

Choose a tag to compare

@akha-security akha-security released this 24 Sep 23:10
· 17 commits to main since this release

Fixed

  • Recursively analyze lazy-loaded JavaScript chunks and retain script dependencies independently from the API-finding confidence threshold.
  • Preserve extra login fields, multi-stage authentication requests, cookies and response bearer tokens during automatic login and reauthentication.
  • Require typed, replayable evidence for GraphQL, WebSocket, API exposure, JWT and authorization findings instead of promoting generic response differences.
  • Reject SQL injection findings based on HTTP 400/422 responses or arithmetic behavior without replay and negative-control proof.
  • Redact JavaScript secret values, nested login credentials, tokens and sensitive report fields by default.

Added

  • Add browser-assisted crawling when direct HTTP requests are blocked, empty or receive browser-solvable responses such as HTTP 403.
  • Add schema-derived, bounded GraphQL probes and typed disclosure checks without treating introspection or generic validation errors as vulnerabilities.
  • Add authenticated multi-step login and bearer-token session support with refreshed credentials propagated into active scan profiles.
  • Add coverage and module-readiness diagnostics to JSON, HTML and Markdown reports, including explicit partial-scan warnings.
  • Add regression coverage for recursive SPA discovery, authenticated sessions, typed verification and report coverage behavior.

Validation

  • Full Go package tests pass with go test ./... -count=1 -timeout=180s.
  • Static analysis passes with go vet ./....
  • Controlled local testlab scan passes.
  • Strict observed benchmark passes with precision, recall and specificity of 1.0 and a false-positive rate of 0 on the available corpus.
  • Windows executable was launched and verified to report AKCA ADVANCED WEB SECURITY SCANNER v0.2.2.

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.1...v0.2.2