Node.Security

Security Audit of Phaser

ISGroup SRL performed an automated Code Review (not a real Static Analysis, more a grep-on-steroid) of this NodeJS project in order to identify potential security vulnerabilities. We do not guarantee that all the findings are valid, and for sure there are plenty of false-positives and false-negatives (undetected issues) but it's free and your project could benefit from this security analisys. The following data is also available in JSON format!

Possible Security Issues
Issue Description Line File
Key Hardcoded A hardcoded key in plain text was identified. 143 docs/scripts/jquery.scrollTo.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 35 docs/scripts/toc.js
Server Side Injection(SSI) - eval() User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 17 docs/scripts/sunlight-plugin.menu.js
Server Side Injection(SSI) - eval() User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 18 docs/scripts/sunlight-plugin.menu.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 294 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 546 docs/scripts/jquery.min.js
Server Side Injection(SSI) - new Function() User controlled data in 'new Function()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 594 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 706 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 720 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 1026 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3153 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3270 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setInterval() User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3417 docs/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 464 docs/scripts/prettify/prettify.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 4 docs/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 5 docs/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 6 docs/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setInterval() User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 6 docs/scripts/prettify/jquery.min.js
Key Hardcoded A hardcoded key in plain text was identified. 4 build/phaser-creature.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 11 build/phaser-creature.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 14 build/phaser-creature.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 15 build/phaser-creature.min.js
Key Hardcoded A hardcoded key in plain text was identified. 20 build/phaser-creature.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 21 build/phaser-creature.min.js
Key Hardcoded A hardcoded key in plain text was identified. 6575 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 11226 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 11237 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 25973 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 26017 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 26435 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 26463 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 26985 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 27018 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 27070 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 27071 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 27096 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 27101 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 33312 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 33318 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 38069 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 38099 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 39250 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 39291 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 48714 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 51495 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 52094 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 56795 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 77730 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79764 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79857 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79931 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 80058 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 80353 build/phaser-creature.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 80390 build/phaser-creature.js
Key Hardcoded A hardcoded key in plain text was identified. 29280 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 33931 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 33942 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 48678 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 48722 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49140 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49168 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49690 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49723 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49775 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49776 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49801 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 49806 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 56017 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 56023 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 60774 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 60804 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 61955 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 61996 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 71419 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 74200 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 74799 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79500 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 100435 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 101987 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 102080 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 102154 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 102281 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 102576 build/phaser.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 102613 build/phaser.js
Key Hardcoded A hardcoded key in plain text was identified. 10 build/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 17 build/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 18 build/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 20 build/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 21 build/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 27 build/phaser.min.js
Key Hardcoded A hardcoded key in plain text was identified. 27 build/phaser.min.js
Key Hardcoded A hardcoded key in plain text was identified. 15667 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 20318 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 20329 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35065 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35109 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35527 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35555 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36077 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36110 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36162 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36163 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36188 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36193 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 42404 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 42410 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 47161 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 47191 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 48342 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 48383 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 57806 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 60587 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 61186 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 65887 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 81392 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 82944 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 83037 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 83111 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 83238 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 83533 build/custom/phaser-arcade-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 83570 build/custom/phaser-arcade-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 6 build/custom/phaser-minimum.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 10 build/custom/phaser-minimum.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 11 build/custom/phaser-minimum.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 12 build/custom/phaser-minimum.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 13 build/custom/phaser-minimum.min.js
Key Hardcoded A hardcoded key in plain text was identified. 6 build/custom/phaser-no-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 14 build/custom/phaser-no-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 16 build/custom/phaser-no-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 17 build/custom/phaser-no-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 18 build/custom/phaser-no-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 19 build/custom/phaser-no-physics.min.js
Key Hardcoded A hardcoded key in plain text was identified. 14467 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 19118 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 19129 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 31448 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 31492 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 31910 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 31938 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32460 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32493 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32545 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32546 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32571 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 32576 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 33417 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 33447 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 34598 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 34639 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 41509 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 44290 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 44889 build/custom/phaser-minimum.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 47435 build/custom/phaser-minimum.js
Key Hardcoded A hardcoded key in plain text was identified. 4 build/custom/phaser-split.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 11 build/custom/phaser-split.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 14 build/custom/phaser-split.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 15 build/custom/phaser-split.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 20 build/custom/phaser-split.min.js
Key Hardcoded A hardcoded key in plain text was identified. 20 build/custom/phaser-split.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 21 build/custom/phaser-split.min.js
Key Hardcoded A hardcoded key in plain text was identified. 6575 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 11226 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 11237 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 25973 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 26017 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 26435 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 26463 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 26985 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 27018 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 27070 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 27071 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 27096 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 27101 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 33312 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 33318 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 38069 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 38099 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 39250 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 39291 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 48714 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 51495 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 52094 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 56795 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 77730 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79282 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79375 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79449 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79576 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79871 build/custom/phaser-split.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 79908 build/custom/phaser-split.js
Key Hardcoded A hardcoded key in plain text was identified. 15667 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 20318 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 20329 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35065 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35109 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35527 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 35555 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36077 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36110 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36162 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36163 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36188 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 36193 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 42404 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 42410 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 47161 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 47191 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 48342 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 48383 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 57806 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 60587 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 61186 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 65887 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 71563 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 71656 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 71730 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 71857 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 72152 build/custom/phaser-no-physics.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 72189 build/custom/phaser-no-physics.js
Key Hardcoded A hardcoded key in plain text was identified. 6 build/custom/phaser-arcade-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 14 build/custom/phaser-arcade-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 16 build/custom/phaser-arcade-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 17 build/custom/phaser-arcade-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 18 build/custom/phaser-arcade-physics.min.js
Key Hardcoded A hardcoded key in plain text was identified. 21 build/custom/phaser-arcade-physics.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 22 build/custom/phaser-arcade-physics.min.js
Key Hardcoded A hardcoded key in plain text was identified. 1098 src/loader/Cache.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 1897 src/loader/Loader.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 2496 src/loader/Loader.js
Key Hardcoded A hardcoded key in plain text was identified. 17 src/gameobjects/RenderTexture.js
Key Hardcoded A hardcoded key in plain text was identified. 23 src/gameobjects/RenderTexture.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 397 src/gameobjects/Video.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 490 src/gameobjects/Video.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 564 src/gameobjects/Video.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 691 src/gameobjects/Video.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 986 src/gameobjects/Video.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 1023 src/gameobjects/Video.js
Key Hardcoded A hardcoded key in plain text was identified. 359 src/gameobjects/GameObjectCreator.js
Key Hardcoded A hardcoded key in plain text was identified. 387 src/gameobjects/GameObjectCreator.js
Key Hardcoded A hardcoded key in plain text was identified. 490 src/gameobjects/GameObjectFactory.js
Key Hardcoded A hardcoded key in plain text was identified. 534 src/gameobjects/GameObjectFactory.js
Key Hardcoded A hardcoded key in plain text was identified. 267 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 300 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 352 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 353 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 378 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 383 src/gameobjects/Button.js
Key Hardcoded A hardcoded key in plain text was identified. 214 src/plugins/weapon/WeaponPlugin.js
Key Hardcoded A hardcoded key in plain text was identified. 41 src/plugins/path/Path.js
Key Hardcoded A hardcoded key in plain text was identified. 46 src/plugins/path/Path.js
Key Hardcoded A hardcoded key in plain text was identified. 1866 src/core/Group.js
Key Hardcoded A hardcoded key in plain text was identified. 1877 src/core/Group.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 1776 src/core/ScaleManager.js
Key Hardcoded A hardcoded key in plain text was identified. 24 src/core/State.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 88 src/utils/RequestAnimationFrame.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 129 src/utils/RequestAnimationFrame.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 585 src/utils/Device.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 615 src/utils/Device.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 5 resources/tutorials/Spanish/02 Creando tu primer juego/js/phaser.min.js
Server Side Injection(SSI) - setInterval() User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 7 resources/tutorials/Spanish/02 Creando tu primer juego/js/phaser.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 8 resources/tutorials/Spanish/02 Creando tu primer juego/js/phaser.min.js
Key Hardcoded A hardcoded key in plain text was identified. 143 resources/docstrap-master/template/static/scripts/jquery.scrollTo.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 35 resources/docstrap-master/template/static/scripts/toc.js
Server Side Injection(SSI) - eval() User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 17 resources/docstrap-master/template/static/scripts/sunlight-plugin.menu.js
Server Side Injection(SSI) - eval() User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 18 resources/docstrap-master/template/static/scripts/sunlight-plugin.menu.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 294 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 546 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - new Function() User controlled data in 'new Function()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 594 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 706 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 720 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 1026 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3153 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3270 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setInterval() User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 3417 resources/docstrap-master/template/static/scripts/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 464 resources/docstrap-master/template/static/scripts/prettify/prettify.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 4 resources/docstrap-master/template/static/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 5 resources/docstrap-master/template/static/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setTimeout() User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 6 resources/docstrap-master/template/static/scripts/prettify/jquery.min.js
Server Side Injection(SSI) - setInterval() User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). 6 resources/docstrap-master/template/static/scripts/prettify/jquery.min.js
Missing Security Features
Issue Description
Missing Security Header - X-Frame-Options (XFO) X-Frame-Options (XFO) header provides protection against Clickjacking attacks.
Missing Security Header - Content-Security-Policy (CSP) Content Security Policy (CSP), a mechanism web applications can use to mitigate a broad class of content injection vulnerabilities, such as cross-site scripting (XSS). CSP Header was not found.
Missing Security Header - Strict-Transport-Security (HSTS) Strict-Transport-Security (HSTS) header enforces secure (HTTP over SSL/TLS) connections to the server.
Missing 'httpOnly' in Cookie JavaScript can access Cookies if they are not marked httpOnly.
Infromation Disclosure - X-Powered-By Remove the X-Powered-By header to prevent information gathering.
Missing Security Header - X-Content-Type-Options X-Content-Type-Options header prevents Internet Explorer and Google Chrome from MIME-sniffing a response away from the declared content-type.
Missing Security Header - X-Download-Options: noopen X-Download-Options header set to noopen prevents IE users from directly opening and executing downloads in your site's context.
Missing Security Header - X-XSS-Protection:1 X-XSS-Protection header set to 1 enables the Cross-site scripting (XSS) filter built into most recent web browsers.
Missing Security Header - Public-Key-Pins (HPKP) Public-Key-Pins (HPKP) ensures that certificate is Pinned.
Outdated Libraries
File Library Reference