Comprehensive security testing platform
This application contains MULTIPLE CRITICAL VULNERABILITIES for testing security scanners.
Do NOT deploy this to production or expose it to the public internet!
Exposed GraphQL endpoint with full schema introspection
/api/graphqlPublicly accessible admin dashboard
/admin/dashboardUnvalidated redirect parameters
/login?next=Exposed .git directory
/.git/configExposed source maps in production
/*.js.mapMissing HSTS, CSP, X-Frame-Options
No headersDeploy this app to Vercel and scan it with the BreakMyApp.ai scanner to verify all vulnerabilities are detected.
Scan URL: https://your-subdomain.vercel.app