shadowauditshadowaudit

Coverage

What we cover — and what we don't

Every shadowaudit finding maps to the OWASP API Security Top 10 (2023). Four categories are in the scanner today. Six are not. This page shows exactly which is which — the rules below are the real heuristics from our MIT-licensed source, not marketing copy.

API9Shadow APIs
core focus

Improper Inventory Management

rule → The reason shadowaudit exists. Undocumented routes, env-only endpoints, stale versions — HIGH + authed + undocumented → API9, INFO undocumented warnings → API9.

API1BOLA
detected

Broken Object Level Authorization

rule → CRITICAL or HIGH + no auth + GET → unauthenticated object access, flagged as BOLA.

API2Broken Auth
detected

Broken Authentication

rule → Per-route auth-state analysis — every finding carries auth: YES/NO. Routes with no auth middleware are the scanner’s primary signal.

API5BFLA
detected

Broken Function Level Authorization

rule → CRITICAL + no auth + POST/PUT/PATCH/DELETE → exposed admin function, flagged as BFLA.

API3BOPLA
not covered

Broken Object Property Level Authorization

Property-level exposure and mass assignment need response-schema analysis — beyond a static route inventory. Out of scope today — and we say so.

API4Consumption
not covered

Unrestricted Resource Consumption

Rate limits and quotas are runtime behavior. A static analyzer can’t measure them. Out of scope today — and we say so.

API6Business Flows
not covered

Unrestricted Access to Sensitive Business Flows

Detecting abnormal business flows requires domain context about what “normal” means for your product. Out of scope today — and we say so.

API7SSRF
not covered

Server Side Request Forgery

We inventory your routes; we don’t trace outbound requests to user-supplied URLs. Out of scope today — and we say so.

API8Misconfig
not covered

Security Misconfiguration

Headers, CORS policies, verbose errors — a different tool category than route auditing. Out of scope today — and we say so.

API10Unsafe Consumption
not covered

Unsafe Consumption of APIs

How your code trusts third-party APIs sits outside your own route inventory. Out of scope today — and we say so.

No security tool covers all ten. The ones that claim broad coverage do it with generic heuristics that flood you with false positives. We'd rather show the gaps than fake them.

Mapping source: src/utils/owasp.ts in the public repo — auditable, MIT licensed.