Understanding findings
1 min read
The five severity levels
- Critical: unauthorized access to real data, or arbitrary code/action execution.
- High: a serious, exploitable flaw, but with narrower exposure or impact than a critical one.
- Medium: a real weakness, usually needing another factor alongside it to be fully exploitable.
- Low: recommended hardening, limited risk in isolation.
- Info: purely informational, nothing exploited or directly exploitable.
The "Active" badge
A finding tagged "Active" could only be detected in active mode: it never shows up on a classic scan. That's what the Pro plan actually buys: not just deeper testing, but classes of issue that are structurally invisible read-only (typically BOLA/IDOR, CSRF, bypassed rate-limits).
The fix
Every finding ships with a plain-language explanation of the real impact and concrete, ready-to-apply remediation steps, never just a generic vulnerability name. For Supabase/RLS findings for example, the fix includes a policy SQL example tailored to the table involved, not an abstract explanation of RLS.
Was this article helpful?