| ASP.NET ViewState Integrity | High | Passive | 642 |
| Heartbleed OpenSSL Vulnerability (Indicative) | High | Passive | 119 |
| JWT Leaked in URL | High | Passive | |
| Open Redirect | High | Passive | 601 |
| Personally Identifiable Information via WebSocket | High | Passive | 359 |
| Script Served From Malicious Domain (polyfill) | High | Passive | 829 |
| Viewstate without MAC Signature (Unsure) | High | Passive | 642 |
| Viewstate without MAC Signature (Sure) | High | Passive | 642 |
| Absence of Anti-CSRF Tokens | Medium | Passive | 352 |
| Application Error Disclosure via WebSockets | Medium | Passive | 209 |
| Authentication Credentials Captured | Medium | Passive | 287 |
| Cookie Containing JWT is Lacking SameSite Attribute | Medium | Passive | 1004 |
| Cookie Containing JWT is Lacking Secure Flag | Medium | Passive | 614 |
Cookie Containing JWT is Lacking __Secure- or __Host- Prefixes | Medium | Passive | 565 |
| Cross-Domain Misconfiguration | Medium | Passive | 264 |
| Directory Browsing | Medium | Passive | 548 |
| HTTP to HTTPS Insecure Transition in Form Post | Medium | Passive | 319 |
| HTTPS to HTTP Insecure Transition in Form Post | Medium | Passive | 319 |
| Information Disclosure - JWT in Browser localStorage | Medium | Passive | 200 |
| Insecure JSF ViewState | Medium | Passive | 642 |
| Java Serialization Object | Medium | Passive | 502 |
| JWT is in Form | Medium | Passive | 522 |
| JWT is in HTTP Header | Medium | Passive | 522 |
| No HttpOnly Flag on Cookie Containing JWT | Medium | Passive | 1004 |
| Missing Anti-clickjacking Header | Medium | Passive | 1021 |
| Potential IP Addresses Found in the Viewstate | Medium | Passive | 642 |
| Emails Found in the Viewstate | Medium | Passive | 642 |
| Session ID in URL Rewrite | Medium | Passive | 200 |
| Reverse Tabnabbing | Medium | Passive | N/A |
| Vulnerable JS Library | Medium | Passive | 829 |
| Weak Authentication Method | Medium | Passive | 326 |
| CSP | Medium | Passive | 693 |
| Big Redirect Detected (Potential Sensitive Information Leak) | Low | Passive | 201 |
| Cookie No HttpOnly Flag | Low | Passive | 1004 |
| Cookie without SameSite Attribute | Low | Passive | 1275 |
| Cookie Without Secure Flag | Low | Passive | 614 |
| Cross-Domain JavaScript Source File Inclusion | Low | Passive | 829 |
| Deprecated Feature Policy Header Set | Low | Passive | 16 |
| Hash Disclosure - MD4 / MD5 | Low | Passive | 200 |
| Information Disclosure - Sensitive Information in Browser Storage | Low | Passive | 200 |
| Information Disclosure - Debug Error Messages | Low | Passive | 200 |
| Information Disclosure - Debug Error Messages via WebSocket | Low | Passive | 200 |
| Multiple HREFs Redirect Detected (Potential Sensitive Information Leak) | Low | Passive | 201 |
| Old Asp.Net Version in Use | Low | Passive | 642 |
| Permissions Policy Header Not Set | Low | Passive | 693 |
| Private IP Disclosure | Low | Passive | 200 |
| Private IP Disclosure via WebSocket | Low | Passive | N/A |
| Secure Pages Include Mixed Content | Low | Passive | 311 |
| Server Leaks Version Information via “Server” HTTP Response Header Field | Low | Passive | 200 |
| Strict-Transport-Security Header | Low | Passive | 319 |
| X-Backend-Server Header Information Leak | Low | Passive | 200 |
| X-Debug-Token Information Leak | Low | Passive | 200 |
| X-AspNet-Version Response Header | Low | Passive | 933 |
| ASP.NET ViewState Disclosure | Informational | Passive | 200 |
| Base64 Disclosure in WebSocket message | Informational | Passive | N/A |
| Content-Type Header Missing | Informational | Passive | 345 |
| Content Security Policy (CSP) Report-Only Header Found | Informational | Passive | 693 |
| Cookie Poisoning | Informational | Passive | 565 |
| Email address found in WebSocket message | Informational | Passive | 200 |
| Image Exposes Location or Privacy Data | Informational | Passive | 200 |
| Information Disclosure - Information in Browser Storage | Informational | Passive | 200 |
| Information Disclosure - JWT in Browser sessionStorage | Informational | Passive | 200 |
| Information Disclosure - Sensitive Information in HTTP Referrer Header | Informational | Passive | 200 |
| Information Disclosure - Sensitive Information in URL | Informational | Passive | 200 |
| Information Disclosure - Suspicious Comments in XML via WebSocket | Informational | Passive | 200 |
| Obsolete Content Security Policy (CSP) Header Found | Informational | Passive | 693 |
| Re-examine Cache-control Directives | Informational | Passive | 525 |
| Server Leaks its Webserver Application via “Server” HTTP Response Header Field | Informational | Passive | 200 |
| Split Viewstate in Use | Informational | Passive | 642 |
| Storable but Non-Cacheable Content | Informational | Passive | 524 |
| User Controllable Charset | Informational | Passive | 20 |
| Username Hash Found | Informational | Passive | 284 |
| Username Hash Found in WebSocket message | Informational | Passive | 284 |
| Verification Request Identified | Informational | Passive | N/A |