Technical Engineering Report
Every engine, suite, finding, evidence object, recommendation, and remediation path
achieveradarsh/chatpdf_backend | 7/30/2026, 4:23:10 PM
70%
Ready With ConditionsRecommendation: Deploy after fixing: identified readiness gaps.
0Critical
0High
4Medium
1Low
Detailed Findings
#1
Suite 14 - Repository Architecture
WARN | medium
Architecture scan found folder-structure or layer-boundary risks.
- Engine
- Architecture
- Evidence
- { "topLevelDirs": [], "cleanArchitectureSignals": [], "dddSignals": [], "microserviceSignals": [], "layerViolations": [], "scannedFiles": 2 }
- Recommendation
- Review the finding, validate exploitability, implement the control, and re-run the relevant validation suite.
- References
- OWASP ASVS, CWE mapping pending, organization policy baseline
#2
Suite 15 - Frontend Security
WARN | medium
Frontend scan found CSP, source map, backend URL, or debug endpoint gaps.
- Engine
- Architecture
- Evidence
- { "scannedFiles": 0, "envFiles": [], "exposedEnvFiles": [], "publicSecretNames": 0, "backendUrls": 0, "debugEndpoints": 0, "dangerousDomApis": 0, "hasCsp": false, "sourceMapsEnabled": false }
- Recommendation
- Review the finding, validate exploitability, implement the control, and re-run the relevant validation suite.
- References
- OWASP ASVS, CWE mapping pending, organization policy baseline
#3
Suite 16 - Backend Security
WARN | medium
Backend scan found missing or undiscovered security controls.
- Engine
- Architecture
- Evidence
- { "hasMiddleware": false, "hasValidation": false, "hasAuthentication": false, "hasAuthorization": false, "hasLogging": false, "hasRateLimiting": false, "hasExceptionHandling": false, "scannedFiles": 0, "missing": [ "hasMiddleware", "hasValidation", "hasAuthentication", "hasAuthorization", "hasLogging", "hasRateLimiting", "hasExceptionHandling" ] }
- Recommendation
- Review the finding, validate exploitability, implement the control, and re-run the relevant validation suite.
- References
- OWASP ASVS, CWE mapping pending, organization policy baseline
#4
Suite 17 - Data Layer
WARN | medium
Data layer scan found missing ORM, pooling, or encryption signals.
- Engine
- Architecture
- Evidence
- { "hasOrm": false, "rawSqlConstruction": 0, "hasPooling": false, "hasEncryption": false, "databaseExposure": 0, "scannedFiles": 2 }
- Recommendation
- Review the finding, validate exploitability, implement the control, and re-run the relevant validation suite.
- References
- OWASP ASVS, CWE mapping pending, organization policy baseline
#5
Suite 18 - Cloud Architecture
WARN | low
No AWS, Azure, or GCP architecture artifacts were found.
- Engine
- Architecture
- Evidence
- {}
- Recommendation
- Review the finding, validate exploitability, implement the control, and re-run the relevant validation suite.
- References
- OWASP ASVS, CWE mapping pending, organization policy baseline