Skip to content

Security: Prem2868/web-vulnerability-scanner

Security

SECURITY.md

Security Policy

Scope

This project is an educational and defensive scanner. Results are heuristics and must be manually validated; the tool must not be treated as proof of exploitability.

Authorized use only

Run scans only against systems you own or are explicitly authorized to test. Do not use this project for unauthorized reconnaissance, denial of service, credential attacks, or data extraction. Prefer local fixtures and intentionally vulnerable training applications when developing or testing changes.

Reporting a vulnerability

Please do not disclose exploitable details in a public issue. Use GitHub's Private vulnerability reporting feature for this repository, and include the affected commit or version, a minimal harmless reproduction, impact, and suggested remediation.

Sensitive data

Never commit credentials, tokens, private URLs, personal data, or scan output containing sensitive information. Redact target details from issues and pull requests.

There aren't any published security advisories