How the security research on this site is sourced, written, reviewed and corrected.
Each vulnerability write-up on the blog starts from a real finding: a vulnerability detected by the Orbis AppSec scanner in a codebase and the fix written for it. Where a fix was opened as a public pull request, the post links to it.
Posts are drafted with AI assistance from the finding, the affected code and the fix, then edited to explain the vulnerability class, why the code was exploitable, and how the fix closes it.
Every post is technically reviewed by Anupam Mediratta, Founder & CTO of Orbis AppSec, before it is published. Review covers the accuracy of the vulnerability description and severity, the root-cause explanation, and whether the fix actually resolves the issue. Posts carry a “Reviewed” date when they are revisited after publication.
If you find an error, email admin@orbisappsec.com with the post URL. We correct factual and technical errors, update the post’s reviewed date, and merge or retire posts that duplicate one another or no longer hold up.
Orbis AppSec sells the scanner these findings come from. Posts describe vulnerabilities and fixes; comparisons with other tools live on clearly labelled product pages, not in research posts.