通用网站安全测试(授权渗透测试)规则与检查清单。当用户要求对网站 / Web 应用做安全测试、漏洞扫描、渗透测试、安全评估,或提到安全测试规则、最小影响测试、隐蔽测试、漏洞复查、授权门禁时使用。核心强调:必须获得授权(默认开启授权门禁,主用非对称签名授权令牌验证 AUTHORIZATION.json + 公钥验签,其余为备选)、最小影响、测试后还原、规范报告、不破坏目标、禁止跳出授权范围(含外站关联尝试须授权,规则 23)。关键词:网站安全测试、授权渗透测试、安全规则、漏洞测试、安全评估、渗透测试规范、web 安全、最小影响、隐蔽测试、授权门禁、签名授权、授权验证、mowenfalse、mow
as observed 2026-09-02T06:49:02.991ZWant to know when this changes? Sign in with an email address and we will tell you. Free, no card, watch up to 5.
web-security-test-rulesFields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"网站测试安全规则 v1.4.9(web-security-test-rules)首次发布\n\n- 提供通用、负责任、最小影响的网站/Web应用安全测试规则与检查清单,强调必须获得明确授权。\n- 默认开启“授权门禁”,主用非对称签名授权令牌验证(AUTHORIZATION.json + 公钥验签),支持多种授权验证和备选降级路径。\n- 明确禁 | "新增规则24-30:定级前核对前端界面/锁定响应IP维度/公开性三问/存储XSS残留物管理/上传校验三档判定/滑块五层测试矩阵/编辑端点归属盲区;检查清单补3条;修复空目录条目导致的install解压失败" |
latestVersion |
"0.1.0" | "0.2.0" |
If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.