Email confirmed
Checking shop.example.com
You can close this tab. The report will open under the link from your email.
- Loading the page
- Downloading JavaScript files
- Detecting the framework and libraries
- Checking known vulnerabilities
- Looking for secrets and source maps
- Checking headers, cookies and TLS
- Writing the report
What we detected
- Framework
- Angular 15.2.10no security fixes since May 2024
- Rendering
- Angular SSR (Express)
- Server
- nginx 1.18.0
- CDN
- Cloudflare
- JavaScript
- 12 files, 3.4 MB
- Libraries
- lodash 4.17.15, moment 2.29.1, RxJS 7.8.0
Findings (10)
Critical 2
CriticalAngular 15 no longer gets security fixesFramework
What we found
<app-root ng-version="15.2.10">Why it matters
Angular 15 left long-term support in May 2024. Vulnerabilities found in the framework since then are fixed only in versions 20, 21 and 22. Your app stays exposed to them.
How to fix it
Upgrade one major version at a time with ng update (15 → 16 → … → 22) and run your tests after each step. From Angular 17 on you can also move to the new control flow and signals.
ng update @angular/core@16 @angular/cli@16CriticalLive Stripe secret key in the JavaScript bundleSecrets
What we found
main.4f2a9c1e.js, line 1: sk_live_51H••••••••••••••••3kQ (we never store the full value)Why it matters
Anyone who opens your site can read this key and use it to issue refunds, read customer data or create charges on your Stripe account.
How to fix it
Revoke the key in the Stripe dashboard today and create a new one. Move every call that needs the secret key to your backend. The frontend should only use the publishable key (pk_live_…).
High 3
HighSource maps are publicly availableSource code
What we found
GET /main.4f2a9c1e.js.map → 200 OK (2.1 MB), plus 11 more .map filesWhy it matters
Source maps rebuild your original TypeScript: file names, comments, internal endpoints and business logic. They make finding the next weakness much easier for an attacker.
How to fix it
Turn off source maps in the production configuration. If you need them for error tracking, upload them to Sentry (or a similar tool) during the build and don't deploy them to the server.
// angular.json → configurations.production
"sourceMap": falseHighXSS protection turned off in 3 placesXSS
What we found
bypassSecurityTrustHtml ×2 (chunk-product.8a1d.js), bypassSecurityTrustResourceUrl ×1 (chunk-cms.19bc.js)Why it matters
These calls tell Angular to skip sanitisation. If the value comes from a user, a CMS or an API, an attacker can inject a script that runs in your customers' browsers.
How to fix it
Check where each value comes from. For HTML from a CMS, bind it with [innerHTML] and let Angular sanitise it. Keep bypassSecurityTrust* only for values your own code builds, and document why.
HighNo Content Security PolicyHeaders
What we found
Response headers of / contain no Content-Security-PolicyWhy it matters
Without CSP the browser runs any injected script. CSP is the second line of defence when an XSS bug gets through.
How to fix it
Start with a report-only policy, fix the reported violations, then enforce it. Angular 19+ can add nonces automatically (autoCsp); in older versions use ngCspNonce.
Content-Security-Policy: script-src 'self' 'nonce-{random}'; object-src 'none'; base-uri 'self'Medium 3
MediumInternal API address in the SSR stateData leak
What we found
<script id="ng-state"> contains "apiBase":"http://10.0.3.14:8080"Why it matters
The page tells every visitor the private address of your API server. On its own it's not an entry point, but it maps your internal network for anyone looking.
How to fix it
Don't put configuration into TransferState. Use a relative path (/api) on the client and keep the internal address in server-side environment variables only.
Mediumlodash 4.17.15 has a known vulnerabilityLibraries
What we found
lodash 4.17.15 in vendor.3c7e.js (CVE-2020-8203, prototype pollution)Why it matters
Code that merges user input with _.zipObjectDeep can change the behaviour of every object in the app.
How to fix it
Update lodash to 4.17.21 or later. Run npm audit in your CI so known vulnerabilities fail the build.
npm install lodash@^4.17.21MediumSession cookie readable from JavaScriptCookies
What we found
Set-Cookie: sid=…; Path=/; Secure (missing HttpOnly and SameSite)Why it matters
Without HttpOnly, a single XSS bug is enough to steal a logged-in session. Without SameSite, the cookie is sent along with requests from other sites (CSRF).
How to fix it
Set the session cookie with HttpOnly, Secure and SameSite=Lax (or Strict) on the backend.
Low 2
Low2 external scripts without integrity checkThird-party scripts
What we found
cdn.jsdelivr.net/npm/swiper@8/swiper-bundle.min.js, cdn.jsdelivr.net/npm/chart.js@3Why it matters
If the CDN or the package is compromised, the modified script runs on your site with full access to the page. It happened with polyfill.io in 2024.
How to fix it
Install these libraries from npm and bundle them with the app, or add integrity and crossorigin attributes with a pinned version.
LowNo security.txtDisclosure
What we found
GET /.well-known/security.txt → 404Why it matters
Researchers who find a vulnerability have no clear way to report it to you, so reports get lost or go public first.
How to fix it
Publish a short file with a contact address and an expiry date.
Contact: mailto:security@shop.example.com
Expires: 2027-09-30T00:00:00.000ZPassed 6
- HTTP redirects to HTTPS
- Only TLS 1.2 and 1.3 enabled
- Certificate valid until 14 January 2027
- Angular runs in production mode
- X-Content-Type-Options: nosniff
- Clickjacking protection (frame-ancestors)
This check covers what is publicly visible: the page, its JavaScript files and HTTP responses. It doesn't cover your source repository, pages behind a login or your backend.
Fix the findings with our Angular team
Talk the findings through with an Angular expert. In 30 minutes you'll know what to fix first and how long the Angular upgrade will take.
- No cost
- No NDA
- No sales reps
