Mobile queries to be removed from preset ALL
List of queries
Language/Group | Removed |
|---|---|
CSharp | CSharp_Windows_Phone | 7 |
Dart | Dart_Mobile_Best_Coding_Practice | 5 |
Dart | Dart_Mobile_High_Risk | 7 |
Dart | Dart_Mobile_Low_Visibility | 17 |
Dart | Dart_Mobile_Medium_Threat | 26 |
Java | Java_Android | 2 |
Kotlin | Kotlin_Android | 32 |
Total | 96 |
CSharp | CSharp_Windows_Phone — 7 queries
ID | Name |
|---|---|
2954 | Client_Side_Injection |
2955 | Unused_Permission |
2956 | Hard_Coded_Cryptography_Key |
2957 | Insecure_Data_Storage |
2958 | Insufficient_Application_Layer_Protect |
2959 | Poor_Authorization_and_Authentication |
2961 | Side_Channel_Data_Leakage |
Dart | Dart_Mobile_Best_Coding_Practice — 5 queries
ID | Name |
|---|---|
7608 | Use_of_Non_Cryptographic_Random |
7662 | Encrypted_Sensitive_Information_in_External_Storage |
7665 | Missing_Certificate_Pinning |
7672 | Deprecated_Functions_or_Properties |
7673 | Unused_Permission |
Dart | Dart_Mobile_High_Risk — 7 queries
ID | Name |
|---|---|
7341 | Resource_Updated_By_URL_Data |
7343 | WebView_JavaScript_Injection_from_URL_Scheme |
7442 | Unsafe_Reflection |
7471 | Sensitive_Information_Exposure_in_Cleartext_Channel |
7628 | Use_of_Hardcoded_Cryptographic_Key_in_Client |
7656 | Unencrypted_Sensitive_Information_in_Publicly_Accessible_Cloud_Storage |
8133 | Absolute_Path_Traversal |
Dart | Dart_Mobile_Low_Visibility — 17 queries
ID | Name |
|---|---|
7313 | Self_SQL_Injection |
7364 | Private_Storage_SQL_Injection |
7393 | Insecure_Android_SDK_Version |
7409 | Use_of_Native_Language |
7412 | Self_WebView_JavaScript_Injection |
7416 | Private_Storage_WebView_JavaScript_Injection |
7468 | Missing_Root_Or_Jailbreak_Check |
7476 | Improper_Resource_Shutdown_or_Release |
7484 | Relative_Path_Traversal |
7506 | Missing_Device_Lock_Verification |
7540 | App_Transport_Security_Disabled |
7555 | User_Information_in_Publicly_Accessible_Storage |
7600 | No_Installer_Verification_Implemented |
7634 | Unencrypted_Sensitive_Information_in_Temporary_File |
7660 | Unencrypted_Sensitive_Information_in_Internal_Storage |
7661 | Encrypted_Sensitive_Information_in_Publicly_Accessible_Cloud_Storage |
7669 | Secret_Stored_Outside_of_Keychain |
Dart | Dart_Mobile_Medium_Threat — 26 queries
ID | Name |
|---|---|
7365 | SQL_Injection_from_URL_Scheme_or_Intent |
7372 | Public_Storage_SQL_Injection |
7405 | Hardcoded_Password_In_Gradle |
7411 | Improper_Certificate_Validation |
7417 | Public_Storage_WebView_JavaScript_Injection |
7421 | Pasteboard_Leakage |
7427 | Poor_Authorization_and_Authentication |
7470 | Information_Exposure_Through_Query_String |
7472 | Communication_Over_HTTP |
7480 | Autocorrection_Keystroke_Logging |
7520 | Sensitive_Information_Through_URL_Scheme |
7541 | Insecure_HTTP_Connections_Enabled |
7610 | Use_of_Cryptographically_Weak_PRNG |
7614 | Use_of_Hardcoded_Salt |
7623 | Use_of_Hardcoded_Cryptographic_IV |
7624 | Broken_or_Risky_Encryption_Algorithm |
7625 | Broken_or_Risky_Hashing_Function |
7626 | Use_Of_Implicit_Intent_For_Sensitive_Communication |
7627 | Insecure_Asymmetric_Cryptographic_Algorithm_Parameters |
7630 | Third_Party_Keyboards_On_Sensitive_Field |
7633 | Insufficiently_Secure_Password_Storage_Algorithm_Parameters |
7635 | Implicit_Intent_With_Read_Write_Permissions |
7655 | Encoding_Used_Instead_of_Encryption |
7657 | Unencrypted_Sensitive_Information_in_External_Storage |
7671 | WebView_Cache_Information_Leak |
8113 | Insecure_WebSocket_Connection |
Java | Java_Android — 2 queries
ID | Name |
|---|---|
7674 | Exported_Content_Provider_Without_Protective_Permissions |
7675 | Exported_Service_Without_Protective_Permissions |
Kotlin | Kotlin_Android — 32 queries
ID | Name |
|---|---|
5638 | Allowed_Backup |
5639 | Debuggable_App |
5641 | Insecure_Android_SDK_Version |
5648 | Hardcoded_Password_In_Gradle |
5649 | ProGuard_Obfuscation_Not_In_Use |
5653 | Use_of_WebView_AddJavascriptInterface |
5685 | Unused_Permission |
5687 | Missing_Rooted_Device_Check |
5691 | DeviceId_Authentication |
5694 | Communication_Over_HTTP |
5719 | Insecure_Cipher_Mode |
5764 | Sensitive_Information_Exposure_in_Cleartext_Channel |
5767 | Webview_DOM_XSS |
5806 | Insecure_Sensitive_Data_Storage |
5807 | Insecure_Data_Storage_Usage |
5821 | Improper_Certificate_Validation |
5825 | Privacy_Violation |
5835 | Screen_Caching |
5840 | Client_Side_Injection |
5862 | Unsafe_Permission_Check |
5872 | Insecure_WebView_Usage |
5873 | Improper_Verification_Of_Intent_By_Broadcast_Receiver |
5882 | Use_Of_Implicit_Intent_For_Sensitive_Communication |
5889 | WebView_Cache_Information_Leak |
5891 | Passing_Non_Encrypted_Data_Between_Activities |
5897 | Client_ReDoS_From_Regex_Injection |
5901 | Non_Encrypted_Data_Storage |
5904 | Reuse_of_Cryptographic_Key |
5915 | Copy_Paste_Buffer_Caching |
7666 | Implicit_Intent_With_Read_Write_Permissions |
7676 | Exported_Service_Without_Protective_Permissions |
7678 | Exported_Content_Provider_Without_Protective_Permissions |