Run #3
completed
Dev (Manus Preview) — https://3000-iwfbndspbd13ykuwl8rr8-c1a65db7.us2.manus.computer
Download Report
16%
Pass Rate
10
Passed
50
Failed
2
Skipped
Filter:
all
pass (10)
fail (50)
error (0)
skip (2)
✗
Homepage loads with 200 OK
Public Marketing & Navigation
502
105ms
✗
Pricing page loads with 200 OK
Public Marketing & Navigation
502
8ms
✗
Privacy policy page loads
Public Marketing & Navigation
502
7ms
✗
Terms of service page loads
Public Marketing & Navigation
502
200ms
✗
Auth page loads
Public Marketing & Navigation
502
96ms
✗
Getting Started page not broken (404 check)
Public Marketing & Navigation
502
94ms
✗
Reseller page not broken (404 check)
Public Marketing & Navigation
502
84ms
✗
Homepage contains key marketing content
Public Marketing & Navigation
502
9ms
✗
Pricing page contains plan names
Public Marketing & Navigation
502
92ms
✓
Response time under 3 seconds
Public Marketing & Navigation
502
89ms
✗
Auth page has Sign In form
Authentication & Onboarding
502
7ms
✗
Auth page has Sign Up option
Authentication & Onboarding
502
7ms
✗
Login with invalid credentials returns error
Authentication & Onboarding
502
10ms
✗
Protected dashboard redirects unauthenticated users
Authentication & Onboarding
502
9ms
✗
Google OAuth endpoint is accessible
Authentication & Onboarding
502
7ms
✗
Password minimum length enforced (8 chars)
Authentication & Onboarding
502
7ms
✗
Logout clears session
Authentication & Onboarding
502
7ms
✗
API returns 401 for unauthenticated tRPC calls
Authentication & Onboarding
502
6ms
✗
Pricing page contains all four plans
Pricing Page
502
6ms
✗
Pricing page shows CAD currency
Pricing Page
502
7ms
✗
Pricing page contains FAQ section
Pricing Page
502
7ms
✗
Pricing page has billing toggle
Pricing Page
502
9ms
✗
Pricing page mentions 17% annual savings
Pricing Page
502
7ms
✗
Dashboard page loads
Agent Configuration
502
6ms
✗
Agent creation endpoint exists
Agent Configuration
502
7ms
✗
Agent settings page accessible after auth
Agent Configuration
502
6ms
✗
tRPC agent listing endpoint responds
Agent Configuration
502
6ms
✗
Analytics API endpoint responds
Dashboard & Analytics
502
11ms
✗
Dashboard shows call statistics section
Dashboard & Analytics
502
7ms
✗
Call history API endpoint responds
Call History & Transcripts
502
7ms
✗
Call history page loads
Call History & Transcripts
502
8ms
✗
Calendar integration settings page accessible
Google Calendar Integration
502
7ms
✗
Google OAuth initiation for calendar
Google Calendar Integration
502
7ms
✗
Notification settings page accessible
Notifications
502
7ms
✗
Homepage serves French content with Accept-Language: fr
Localisation (EN/FR/ES)
502
7ms
✗
Pricing page serves French content
Localisation (EN/FR/ES)
502
7ms
✗
Homepage serves Spanish content with Accept-Language: es
Localisation (EN/FR/ES)
502
8ms
✗
Language preference persisted in URL or cookie
Localisation (EN/FR/ES)
502
7ms
✓
A01 - Broken Access Control: Unauthenticated access to protected API
OWASP Top 10 Security
502
7ms
✗
A02 - Cryptographic Failures: HTTPS enforced
OWASP Top 10 Security
502
13ms
✗
A02 - Cryptographic Failures: Secure cookie attributes
OWASP Top 10 Security
502
7ms
✓
A03 - Injection: XSS via query parameters
OWASP Top 10 Security
502
8ms
✗
A03 - Injection: SQL injection probe on auth endpoint
OWASP Top 10 Security
502
7ms
✗
A04 - Insecure Design: Registration without email verification
OWASP Top 10 Security
502
27ms
✓
A05 - Security Misconfiguration: Server version headers not exposed
OWASP Top 10 Security
502
6ms
✓
A05 - Security Misconfiguration: CORS policy is restrictive
OWASP Top 10 Security
502
11ms
–
A06 - Vulnerable Components: No sensitive data in client bundle
OWASP Top 10 Security
7ms
✗
A07 - Identification & Auth Failures: Rate limiting on login
OWASP Top 10 Security
502
158ms
✗
A07 - Identification & Auth Failures: Password reset token expiry
OWASP Top 10 Security
502
8ms
✗
A08 - Software & Data Integrity: Content Security Policy header present
OWASP Top 10 Security
502
6ms
✗
A09 - Security Logging Failures: 404 errors are logged
OWASP Top 10 Security
502
36ms
✓
A10 - SSRF: External URL parameter not exploitable
OWASP Top 10 Security
502
7ms
✓
LLM01 - Prompt Injection: Malicious instruction in caller input
OWASP Top 10 for AI (LLM Applications)
502
7ms
✓
LLM02 - Sensitive Information Disclosure: AI does not leak PII
OWASP Top 10 for AI (LLM Applications)
502
6ms
–
LLM03 - Supply Chain: Third-party AI model dependencies disclosed
OWASP Top 10 for AI (LLM Applications)
7ms
✗
LLM04 - Data and Model Poisoning: Call data isolation between accounts
OWASP Top 10 for AI (LLM Applications)
502
6ms
✗
LLM05 - Improper Output Handling: AI output is sanitized before display
OWASP Top 10 for AI (LLM Applications)
502
12ms
✓
LLM06 - Excessive Agency: AI cannot perform unauthorized actions
OWASP Top 10 for AI (LLM Applications)
502
7ms
✓
LLM07 - System Prompt Confidentiality: System prompt not exposed via API
OWASP Top 10 for AI (LLM Applications)
502
6ms
✗
LLM08 - Vector and Embedding Weaknesses: Call data not accessible via embedding search
OWASP Top 10 for AI (LLM Applications)
502
7ms
✗
LLM09 - Misinformation: AI call summary accuracy indicators
OWASP Top 10 for AI (LLM Applications)
502
6ms
✗
LLM10 - Unbounded Consumption: API rate limiting on AI endpoints
OWASP Top 10 for AI (LLM Applications)
502
157ms
Run started: 3/18/2026, 8:04:11 PM · Completed: 3/18/2026, 8:04:14 PM