Platform Update16 September 2026

Every Report Now Includes an Explicit OWASP Top 10:2025 Coverage Checklist

Every Report Now Includes an Explicit OWASP Top 10:2025 Coverage Checklist

Every Report Now Includes an Explicit OWASP Top 10:2025 Coverage Checklist

Every Decloak report now includes an explicit OWASP Top 10:2025 coverage checklist, a fixed list of all 10 OWASP categories, each marked with what actually happened on that scan.

Instead of having to infer "does this actually cover OWASP?" from scattered finding categories scattered across a report, it's now a citable, literal checklist, 10 rows, always present, on every report you generate.

Why "not tested" is the part worth understanding

Four categories are honestly marked not tested by default, each with its own stated reason right on the checklist:

This is a deliberate honesty choice, not a gap we're trying to hide. Most scanners either silently skip categories they can't test, leaving you to assume coverage that was never there, or overclaim coverage they don't actually have. Stating plainly why something is out of scope for black-box external scanning is a trust signal, not a weakness, and it's a more useful answer than either silence or a false claim.

Built on the current standard, not a four-year-stale one

While building this, we found that our own existing CWE/OWASP reference table was still citing OWASP Top 10:2021. OWASP finalized the 2025 edition in January 2026, and the changes are substantial enough to matter: SSRF was folded into Broken Access Control, Insecure Design and Authentication Failures got renumbered, and there's an entirely new category, Mishandling of Exceptional Conditions. We rebuilt the whole mapping on 2025, so Decloak now cites the current standard rather than one that had already gone stale.

How the mapping actually works

Every Decloak finding category, Missing Header, JavaScript CVE, SQL Injection, and around 36 others, already maps to one CWE and one OWASP category in a single central mapping table. The OWASP checklist simply re-groups that same table by OWASP category instead of by finding category, one source of truth, so the checklist and the existing CVE/CWE/OWASP reference table can never drift apart from each other.

While rebuilding this, we also found, and fixed, three AI Pentesting finding categories, SQL Injection, Cross-Site Scripting, and JWT Weak Secret, that had never been mapped to any standard at all. Worth fixing regardless of the OWASP checklist specifically, but this work is what surfaced it.

Where you'll see it

In the web report, its own collapsible section, "OWASP Top 10 Coverage Checklist," on both the free single-page report and the paid agent report, sitting right after Known Vulnerabilities and before Platform Security. Each row expands to show the actual finding titles behind a Confirmed category.

In the PDF, its own appendix section right after the CVE/CWE/OWASP References table, in all four PDF types, the free report, the paid agent report, the Active Testing report, and the AI Pentesting report.

Availability

Unlike the SOC 2, ISO 27001, NIS2, DORA, LGPD, and PCI DSS compliance control mapping, which is Pro and above, the OWASP Top 10:2025 checklist is unlocked on every plan, including free. It's reflected in the pricing table, the features page, how-it-works, the homepage, the FAQ, and a dedicated help guide.


The OWASP Top 10:2025 coverage checklist is included on every report, on every plan. Scan your site free →