Information Disclosure: Sensitive Comments¶
Identifier:
sensitive_comments
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
Sensitive comments in source code may unintentionally reveal details about application internals, security weaknesses, or design flaws that attackers could exploit.
How we test: We analyze source code and HTML comments in responses to detect sensitive information such as credentials, API keys, internal architecture details, or debugging information that shouldn't be exposed. We check for comments containing passwords, secrets, or other sensitive data that could aid attackers.
Configuration¶
Example¶
Example configuration:
Reference¶
skip¶
Type: boolean
Skip the test if true.