vc-platform
vc-platform copied to clipboard
ZAP Scan Baseline Report
- Site: https://vcptcore-dev.govirto.com
New Alerts
- CSP: Wildcard Directive [10055] total: 2:
- CSP: script-src unsafe-inline [10055] total: 2:
- CSP: style-src unsafe-inline [10055] total: 2:
- Sub Resource Integrity Attribute Missing [90003] total: 2:
- Cross-Domain JavaScript Source File Inclusion [10017] total: 2:
-
Dangerous JS Functions [10110] total: 4:
- https://vcptcore-dev.govirto.com/dist/app.js?v=QcIhMqmMPTnqdP_Lm-dvfqW-eExW_BvdhEv4-GJJ6jc
- https://vcptcore-dev.govirto.com/dist/vendor.js?v=CrgXH2EvizBu-H2lezNUn_MMVPmmzwrPvCcvlbUoFiQ
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.CustomerExportImport)/dist/app.js?v=Ni_H73ZpsMtyr-0vdYbdGkX63Ix8m5ENPcDgNCPg2UQ
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Notifications)/dist/app.js?v=Gx54drFiY-ENv-Be4qH5jfR-YiymsQdgVlCIOfmDKjM
-
Permissions Policy Header Not Set [10063] total: 11:
- https://vcptcore-dev.govirto.com
- https://vcptcore-dev.govirto.com/
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Assets)/dist/app.js?v=CUBQus5NuARE0JP9znNYzikAV0QOTQ4YnR6yXdr2o5w
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Core)/dist/app.js?v=GMMit6HpV34jawzXX2RVzs2TJBmYycnES02Q3UrXbJk
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Customer)/dist/app.js?v=CHDckbHr7cbF8KL4zci0HtdT-tQbgXXEQi5aNu7caKM
- ..
- Timestamp Disclosure - Unix [10096] total: 1:
-
Base64 Disclosure [10094] total: 12:
- https://vcptcore-dev.govirto.com
- https://vcptcore-dev.govirto.com
- https://vcptcore-dev.govirto.com/
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Catalog)/dist/style.css?v=Z_wcrI_74CPpGEznTeEexg7SU5lYBVj53SZZ2ZjvZ40
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Content)/dist/style.css?v=W-ZSCF_AdUts-t2_DjAEWtDegp-FsKjC4ncgpOuB07Y
- ..
-
Information Disclosure - Suspicious Comments [10027] total: 11:
- https://vcptcore-dev.govirto.com
- https://vcptcore-dev.govirto.com/
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Assets)/dist/app.js?v=CUBQus5NuARE0JP9znNYzikAV0QOTQ4YnR6yXdr2o5w
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Catalog)/dist/app.js?v=QtPLQUAKQR5lVAlUJ1zlND28EzAB_BfPPhFw8gYORtM
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Content)/dist/app.js?v=YEy9Co-n-ROPmErKbBUEvvueCQk4oW5XIu3oYq_RgzE
- ..
- Modern Web Application [10109] total: 2:
- Re-examine Cache-control Directives [10015] total: 3:
- Sec-Fetch-Dest Header is Missing [90005] total: 3:
- Sec-Fetch-Mode Header is Missing [90005] total: 3:
- Sec-Fetch-Site Header is Missing [90005] total: 3:
- Sec-Fetch-User Header is Missing [90005] total: 3:
-
Storable and Cacheable Content [10049] total: 11:
- https://vcptcore-dev.govirto.com
- https://vcptcore-dev.govirto.com/
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Catalog)/dist/style.css?v=Z_wcrI_74CPpGEznTeEexg7SU5lYBVj53SZZ2ZjvZ40
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Content)/dist/style.css?v=W-ZSCF_AdUts-t2_DjAEWtDegp-FsKjC4ncgpOuB07Y
- https://vcptcore-dev.govirto.com/modules/$(VirtoCommerce.Customer)/dist/style.css?v=VexL7D7TvPYyKPfzXG32PVA8ZNJt_Q4e5C9PZXQr3G8
- ..
View the following link to download the report. RunnerID:10285515353
ZAP is supported by the Crash Override Open Source Fellowship