Critical

Showing all detectors for the JavaScript language with critical severity.

Hardcoded credentials

Hardcoded credentials can be intercepted by malicious actors.

Unsanitized input is run as code

Scripts generated from unsanitized inputs can lead to malicious behavior and inadvertently running code remotely.

Insecure cryptography

Weak, broken, or misconfigured cryptography can lead to security vulnerabilities.

Session fixation

Session fixation might allow an attacker to steal authenticated session IDs.