v0.59.0: 8 New Security Tools (446 Total)
·
22 commits
to main
since this release
What's New in v0.59.0
8 New Security Analysis Tools
- cors_safelist - Analyze CORS safelist bypass: wildcard origin, origin reflection, null origin.
- iframe_sandbox_policy - Analyze iframe sandbox policy: missing sandbox, allow-scripts+same-origin combo.
- report_to_header - Analyze Report-To header: missing group, invalid endpoint, deprecated report-uri.
- nel_header - Analyze NEL header: missing report_to, invalid config, sampling rate.
- expect_ct_header - Analyze Expect-CT header: missing enforce, max-age too short, CT enforcement.
- cors_credentials - Analyze CORS credentials: wildcard+credentials, missing allow-credentials, insecure HTTP.
- service_worker_scope - Analyze service worker scope: missing scope, broad root scope, HTTP registration.
- client_hints - Analyze client hints: missing hints, insecure hints, critical-CH config.
Total: 446 tools