1
Critical Findings
ERROR severity
0
Warnings
WARNING severity
0
Dep. CVEs
Known vulnerabilities
1
ATT&CK Techniques
Unique techniques
N/A
Sandbox Exit
Not executed
⚡ Threat Level
Score 10/100
Composite Risk Score
LOW
Low (0-19) Medium (20-44) High (45-69) Critical (70-100)
Critical Weight
10
1 errors x 10 pts
Warning Weight
0
0 warnings x 3 pts
CVE Weight
0
0 CVEs x 8 pts
Runtime Weight
0
0 behaviors x 15 pts
Priority Fix Queue (Top 5 Critical)
#RuleFileCWETechnique
1 r :1 CWE-89 T1059
🎯 Attack Surface Analysis
🗄
SQL Injection
Exposed
CWE-89 / T1190 Initial Access
💻
Command Injection
Clear
CWE-78 / T1059 Execution
📜
Cross-Site Scripting
Clear
CWE-79 / T1059.007 Execution
🌐
SSRF
Clear
CWE-918 / T1090 Defense Evasion
📁
Path Traversal
Clear
CWE-22 / T1083 Discovery
🔑
Hardcoded Credentials
Clear
CWE-798 / T1552.001 Credential Access
🔒
Weak Cryptography
Clear
CWE-327 / T1600 Defense Evasion
📦
Insecure Deserialization
Clear
CWE-502 / T1059 Execution
📈 Analysis Charts
Severity Distribution
ATT&CK Technique Radar
Findings by File
Severity per File (Top 6)
Language Risk Distribution
CWE Category Breakdown
Tactic Phase Distribution
📋 Repository Information
No description provided.
Stars 0 Forks 0 Watchers 0 Issues 0 Size 0 KB
Details
OwnerN/A
Default Branchmain
LicenseNone
CreatedN/A
Last PushN/A
Size0 KB
Language Breakdown

No language data available.

Recent Commits

No commit data.

Contributors

No contributor data.

🛡 MITRE ATT&CK Coverage
1 techniques
T1059
CSI
Execution
1
🔍 Vulnerability Findings
1 total
SeverityRule / DescriptionLocationMITRE
ERROR r
x
L1
CWE-89 T1059 Execution
📦 Dependency CVEs
0
No known CVEs detected in dependencies.
🐳 Sandbox Runtime Analysis
Sandbox not enabled for this scan. Re-run with Docker Sandbox option active.
🧬 Ransomware Intelligence
Ransomware analysis not available for this scan.
🔑 Secrets Detection
Secrets scan not included in this report.
📦 Dependency Vulnerabilities
Dependency scan not included in this report.
🏗️ IaC Misconfiguration Scanner
IaC scan not included in this report.
📋 Compliance Mapping
1/1 mapped · 100.0% coverage

Findings mapped to PCI DSS v4.0, NIST SP 800-53 Rev 5, OWASP Top 10 (2021), and SANS/CWE Top 25.

OWASP Top 10
A03:2021 - Injection1
PCI DSS v4.0
Req 6.2.41
NIST 800-53
SI-101
SANS/CWE Top 25
#3 · CWE-891
⚖️ License Compliance
1 packages
1
High risk (copyleft)
0
Medium risk
1
Total packages
PackageVersionLicenseRisk
gpllib 1.0 GPL-3.0 HIGH
📦 Software Bill of Materials
CycloneDX 1.4 · 1 components
1
Components
0
Vulnerabilities
1.4
CycloneDX

Machine-readable inventory — compatible with Dependency-Track, grype, trivy and the GitHub Dependency Submission API.

ComponentVersionPURL
flask 2.0 pkg:pypi/flask@2.0
🔗 Supply-Chain Risk
2 risks

Detects typosquatting (package names mimicking popular libraries) and dependency confusion (internal-looking names that also exist on public registries).

TypeEcosystemPackage / DetailRisk
typosquat python reqeusts — mimics requests HIGH
confusion npm internal-lib — public 9.9 vs required 1.0 MEDIUM
🏅 Project Health — OpenSSF Scorecard
6.4/10
6.4
out of 10
Aggregate OpenSSF Scorecard for the repository — measures maintenance, code review, branch protection, signed releases, dependency update tooling and more. Last evaluated 2026-07-01.
CheckScoreReason
Branch-Protection 8 enabled
Signed-Releases 2 no signed releases
Fuzzing N/A not run
🐳 Container Image Scan
1 findings
SeverityPackageVulnerabilityVersionFixed
HIGH openssl CVE-2023-1 openssl flaw 1.1.1 1.1.1t