Product
SAST Coverage & Rules Zero-Day Discovery Download
Compliance
Compliance Hub OWASP Top 10 CWE Top 25 PCI DSS 4.0.1 MISRA C / C++ 2023 AUTOSAR C++14 ISO 26262 SEI CERT
Compare
vs All SAST Tools vs Coverity vs Veracode vs Snyk vs Mythos AI vs GPT-5.4 Cyber Download
Compliance  /  OWASP Top 10
OWASP Top 10

Every category,
covered across 16 languages.

PhantomYerra detects and maps findings to all ten OWASP Top 10 web application security risk categories, by CWE and finding class, with a one-click OWASP compliance report.

10 / 10
categories covered
16
languages
24,476
detection rules

Coverage by OWASP Top 10 category

IDCategoryCoveredWhat PhantomYerra detects
A01Broken Access ControlYesMissing/broken authz, IDOR, path traversal, CSRF, mass assignment
A02Cryptographic FailuresYesWeak ciphers/hashes, plaintext transport, hardcoded keys, weak RNG
A03InjectionYesSQL/command/LDAP/NoSQL/code injection, XSS, SSTI
A04Insecure DesignYesDangerous defaults, missing validation patterns
A05Security MisconfigurationYesDebug enabled, permissive CORS, insecure cookies, XXE
A06Vulnerable & Outdated ComponentsYesSCA + SBOM + advisory matching
A07Identification & Auth FailuresYesBroken auth, session fixation, JWT alg-none
A08Software & Data Integrity FailuresYesInsecure deserialization, gadget chains, supply chain
A09Logging & Monitoring FailuresYesMissing/over-verbose logging, log injection
A10Server-Side Request ForgeryYesSSRF sinks across languages

Turn findings into OWASP Top 10 evidence

Every PhantomYerra finding carries its CWE and the standard IDs it satisfies, so a one-click compliance report maps findings to OWASP Top 10 automatically - alongside the EU Cyber Resilience Act and more.