Reproducible accuracy
We run the industry-standard OWASP Benchmark and publish every number — including the categories where we still have work to do. Re-run it yourself with one command.
| Category | Score | Recall | Precision | FPR |
|---|---|---|---|---|
| Weak Randomness | 1.000 | 100.0% | 100.0% | 0.0% |
| Weak Cryptography | 0.808 | 80.8% | 100.0% | 0.0% |
| Weak Hashing | 0.690 | 69.0% | 100.0% | 0.0% |
| Cross-Site Scripting | 0.516 | 57.3% | 92.2% | 5.7% |
| XPath Injection | 0.467 | 46.7% | 100.0% | 0.0% |
| Command Injection | 0.451 | 57.9% | 82.0% | 12.8% |
| Path Traversal | 0.445 | 53.4% | 85.5% | 8.9% |
| SQL Injection | 0.303 | 39.0% | 84.1% | 8.6% |
| Trust Boundary | 0.237 | 47.0% | 79.6% | 23.3% |
| LDAP Injection | 0.000 | 0.0% | — | 0.0% |
| Insecure Cookie | 0.000 | 0.0% | — | 0.0% |
Score is Youden’s J (recall − false-positive rate), with strict OWASP CWE-per-category matching. Categories at 0.00 (LDAP / XPath injection, insecure cookie) are honestly reported — rules for those are on the roadmap.
Engine: SAST — regex + intra-file taint + dataflow (constant-fold / key-sensitive). Environment: 4 vCPU, go1.25.1, Linux. The archive is versioned and served at /api/benchmark.