Skip to main content

Managed Security Review for Web Applications

info

The English user guide is currently in beta preview. Most of the documents have been automatically translated from the Japanese version. Should you find any inaccuracies, please reach out to Flatt Security.

This page explains managed security reviews for Web applications provided by Flatt Security. Note that Flatt Security may provide more policies than ones described here, depending on your support plans.

info

Managed security reviews for web applications will continue to be expanded, and this page will be updated accordingly. For the latest roadmap regarding the expansion of managed security reviews, please reach out to Flatt Security.

All managed review items

TitleID in Shisho Cloud
Protect from eval injectiondecision.api.shisho.dev/v1beta:web_eval_injection
Ensure GraphQL introspection is disableddecision.api.shisho.dev/v1beta:web_graphql_introspection_query
Fix HTML injection vulnerabilitydecision.api.shisho.dev/v1beta:web_html_injection
Fix Local File Inclusion vulnerabilitydecision.api.shisho.dev/v1beta:web_lfi
Fix header injection vulnerabilitydecision.api.shisho.dev/v1beta:web_location_header_injection
Fix open redirect vulnerabilitydecision.api.shisho.dev/v1beta:web_open_redirect
Protect from OS command injectiondecision.api.shisho.dev/v1beta:web_osci
Ensure CORS is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_access_control_allow_origin
Ensure Cache-Control headers are appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cache_control
Ensure charset is specifieddecision.api.shisho.dev/v1beta:web_passive_charset
Protect from click jackingdecision.api.shisho.dev/v1beta:web_passive_click_jacking
Ensure Content Security Policy is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_content_security_policy
Ensure Content-Type header is setdecision.api.shisho.dev/v1beta:web_passive_content_type
Ensure the HttpOnly attribute of Cookies are appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cookie_httponly
Ensure the SameSite attribute of Cookies are appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cookie_samesite
Ensure the Secure attribute of Cookies are appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cookie_secure
Ensure that Cross-Origin-Opener-Policy is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cross_origin_opener_policy
Ensure that Cross-Origin-Resource-Policy is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_cross_origin_resource_policy
Ensure data beneficial for attackers are not exposeddecision.api.shisho.dev/v1beta:web_passive_data_exposure_benefiting_attackers
Ensure personal data are not exposeddecision.api.shisho.dev/v1beta:web_passive_data_exposure_personal
Ensure debug information is not exposeddecision.api.shisho.dev/v1beta:web_passive_debug_message
Disable unintended directory browsingdecision.api.shisho.dev/v1beta:web_passive_directory_browsing
Ensure HSTS header is configured appropriatelydecision.api.shisho.dev/v1beta:web_passive_hsts
Ensure that Referrer-Policy is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_referrer_policy
Ensure that X-Content-Type-Options is appropriately configureddecision.api.shisho.dev/v1beta:web_passive_x_content_type_options
Fix SQL injection vulnerabilitydecision.api.shisho.dev/v1beta:web_sqli
Protect from SSRF vulnerabilitydecision.api.shisho.dev/v1beta:web_ssrf
Fix Server-Side Template Injection vulnerabilitydecision.api.shisho.dev/v1beta:web_ssti
Fix XPath injection vulnerabilitydecision.api.shisho.dev/v1beta:web_xpath_injection
Fix XSS vulnerabilitydecision.api.shisho.dev/v1beta:web_xss
Fix XXE vulnerabilitydecision.api.shisho.dev/v1beta:web_xxe