Understanding findings

1 min read

The five severity levels

  • Critical: unauthorized access to real data, or arbitrary code/action execution.
  • High: a serious, exploitable flaw, but with narrower exposure or impact than a critical one.
  • Medium: a real weakness, usually needing another factor alongside it to be fully exploitable.
  • Low: recommended hardening, limited risk in isolation.
  • Info: purely informational, nothing exploited or directly exploitable.

The "Active" badge

A finding tagged "Active" could only be detected in active mode: it never shows up on a classic scan. That's what the Pro plan actually buys: not just deeper testing, but classes of issue that are structurally invisible read-only (typically BOLA/IDOR, CSRF, bypassed rate-limits).

The fix

Every finding ships with a plain-language explanation of the real impact and concrete, ready-to-apply remediation steps, never just a generic vulnerability name. For Supabase/RLS findings for example, the fix includes a policy SQL example tailored to the table involved, not an abstract explanation of RLS.

Was this article helpful?