---
title: "Live App Probing (DAST) | ShipSafe"
description: "Non-destructive dynamic checks against a running app: security headers, Content-Security-Policy quality, clickjacking, CORS, exposed files, and leaked stack traces."
doc_version: 2026-10-05
last_updated: 2026-10-05T14:17:03.687Z
canonical: https://ship-safe.co/docs/dast-scanning
---

# Live App Probing (DAST) | ShipSafe

● Live App Probing (DAST)

# Test it running.

Dynamic Application Security Testing (DAST) checks the issues that only exist at runtime, the ones a static scan of your code can never see, by making real requests to your running app. ShipSafe's DAST is non-destructive: GET requests only, bounded and rate-limited, nothing that changes your data.

## What it checks

Security headers

HSTS, X-Content-Type-Options, X-Frame-Options / frame-ancestors, Referrer-Policy.

CSP quality

Flags a missing policy, and weak ones that allow 'unsafe-inline' or 'unsafe-eval'. Honors a CSP set via a <meta> tag, not just a header.

Clickjacking

No X-Frame-Options and no CSP frame-ancestors means your page can be framed.

Cookie flags

Set-Cookie missing Secure, HttpOnly, or SameSite.

CORS

Reflecting an arbitrary Origin with credentials, the classic account-data leak.

Exposed paths

/.env, /.git/config, backups, /admin, and other things that should never be public. From your own machine, via the CLI or MCP, this always runs against a target you attest you own. From ShipSafe's hosted servers — including the Live URL scan on the web — it runs only once your account has proven it controls the target origin; otherwise the hosted scan skips it.

Info disclosure

Server stack traces and directory listings leaking internal detail.

HEADS UP· Consent is required

Only probe an app you own or are explicitly authorized to test. Probing systems you do not control is unauthorized scanning. Every entry point requires you to confirm authorization, and ShipSafe refuses targets on private, internal, or cloud-metadata addresses.

## Run it from your editor (MCP)

AGENT

Copy

```text
shipsafe_dast
  url: "http://localhost:3000"
  confirmOwnership: true
```

Point it at your local dev server before you ship, or at a deployed URL you own. For deployed apps, the [Live URL scan](https://ship-safe.co/docs/live-url-scanning) runs these checks plus a client-bundle secret scan in one pass.

NOTE· The API is the bigger surface

DAST covers your front-end runtime. The highest-impact bugs (IDOR, broken auth) live in your backend API and need authenticated, separately-scoped testing. Treat a clean DAST pass as necessary, not sufficient.

[← PreviousLive URL Scan](https://ship-safe.co/docs/live-url-scanning)[Next →Git History Secrets](https://ship-safe.co/docs/git-history-scanning)

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
