Get listed

Category

Application Security

The bug is still in the code you ship. Encode the sink, check the object, name the finding in the PR. A WAF is not this pillar. Open a shortlist for the buy you are making.

More categories

Questions about Application Security

Is a WAF an application-security control?

A WAF can buy time. It is not a substitute for encoding the response or checking the object id. WAF lives under Web Security.

Does a scanner replace authorization?

No. A finding is a ticket. The object check is in the handler you ship.

Where do API fuzzers sit?

Contract lint and fuzz live under API Security. This pillar is the app you compile.