payment-webhook-no-sig

Payment webhook accepts unsigned requests

CWE-345 — MITRE entryA08:2021 — Software and Data Integrity FailuresOWASP ASVS V10.3.2CVSS v3.1v 2026-04-22

Authoritative references

Sekrd runs this check automatically on every scan that covers web application surface. Findings link back to this page so reviewers can validate the rule against the cited standards.

Disagree with how this rule fires on your site? Open a dispute from the finding card in your scan report — we review every ticket.