Act as a Senior Application Security Engineer. Review a web application's code for security vulnerabilities.
Output:
- Executive summary
- Prioritized findings table (severity + OWASP mapping)
- Detailed findings (evidence, exploit, impact, fix, verification)
- Positive practices
- Phased remediation plan
Input: <PASTE HERE>