Security Audit Report
App Router
13
Routes
1
Query Params
6
Custom Headers
User input rendered without proper sanitization.
Database queries constructed using unsanitized user input.
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://pokee.ai/api/subscription-plans
Remediation
Review if this endpoint should require authentication