WSTG-INFO Information Gathering Fingerprint stack, metafiles, JS leakage, architecture mapping | Partial | - · WSTG-INFO-01 robots
- · WSTG-INFO-08 disclosure
- · source maps
- · host fingerprint
| Black-box homepage + passive host; not Google/GitHub/subdomain brute |
WSTG-CONF Configuration & Deployment TLS, HTTP methods, debug surfaces, file exposure, security headers | Covered | - · WSTG-CONF-04 exposed paths
- · WSTG-CONF-06 methods
- · WSTG-CONF-07 HSTS
- · WSTG-CONF-12 CSP
| Core of the free + full black-box suite |
WSTG-IDNT Identity Management Registration, account enumeration, provisioning | Out of scope | - · duplicate registration
- · username enum
- · weak email verify
| Needs account lifecycle tests against the app |
WSTG-ATHN Authentication Credential transport, lockout, MFA, default creds | Partial | - · WSTG-ATHN-01 rate-limit (opt-in)
- · TLS for credential channel
| Not full login abuse; WorkOS owns hosted auth |
WSTG-ATHZ Authorization Privilege escalation, IDOR, path traversal | Partial | - · WSTG-ATHZ-04 IDOR via idorProbe
- · rbacProbe
| White-box helpers — not automatic from a single URL |
WSTG-SESS Session Management Cookie flags, fixation, CSRF, logout | Partial | - · WSTG-SESS-02 cookies
- · WSTG-SESS-05 CSRF heuristic
- · WSTG-SESS-10 JWT
| Cookie/JWT/CSRF heuristics; not fixation or logout flows |
WSTG-INPV Input Validation XSS, SQLi, SSRF, SSTI, LFI, command injection | Partial | - · WSTG-CLNT-01 DOM-XSS heuristic
- · WSTG-INPV-17 host-header
| No active payload fuzzing (by design on production targets) |
WSTG-ERRH Error Handling Stack traces, verbose errors, information leakage | Covered | - · WSTG-ERRH-01 stack traces
| When error pages leak internals |
WSTG-CRYP Cryptography Weak TLS, bad crypto, secrets in transit/storage | Partial | - · WSTG-CRYP-01 TLS
- · WSTG-CRYP-03 channel
- · WSTG-CRYP-04 client secrets
| Transport + client-exposed secrets; not server-side crypto review |
WSTG-BUSL Business Logic Workflow abuse, races, price tampering, upload abuse | Out of scope | - · checkout skip
- · race on quotas
- · file upload
| Manual / product-specific E2E |
WSTG-CLNT Client-side DOM XSS, clickjacking, CORS, storage, SRI | Covered | - · WSTG-CLNT-01
- · WSTG-CLNT-04 open redirect
- · WSTG-CLNT-07 CORS
- · WSTG-CLNT-09 clickjacking
- · WSTG-CLNT-11 SRI
| Strong black-box coverage of client surface |
WSTG-APIT API Testing REST/GraphQL authz, mass assignment, inventory | Partial | - · GraphQL introspection
- · swagger exposure
- · API1 via idorProbe
- · mass assignment helper
| Public misconfig automatic; BOLA needs two sessions |