{"id":53379,"date":"2014-05-19T14:18:58","date_gmt":"2014-05-19T14:18:58","guid":{"rendered":"https:\/\/www.checkmarx.com\/?post_type=glossary&#038;p=8438"},"modified":"2026-04-13T22:57:56","modified_gmt":"2026-04-13T20:57:56","slug":"vulnerability-assessment-and-penetration-testing","status":"publish","type":"glossary","link":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/","title":{"rendered":"What Is VAPT (Vulnerability Assessment &amp; Penetration Testing)?"},"content":{"rendered":"<p>VAPT combines two complementary practices: a vulnerability assessment to identify known weaknesses at scale and a penetration test to safely exploit and validate real-world impact. Together, they give teams a prioritized view of risk and help prove which findings truly matter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\"><strong>VAPT in AppSec: Where It Fits<\/strong><\/h2>\n\n\n\n<p>VAPT is typically performed against running systems, apps, APIs, and infrastructure to validate security controls and quantify exploitability. In modern software delivery, it works best alongside shift-left testing methods like <a href=\"https:\/\/checkmarx.com\/learn\/sast\/static-application-security-testing-sast\/\">SAST<\/a>, <a href=\"https:\/\/checkmarx.com\/learn\/software-composition-analysis\/software-composition-analysis-sca\/\">SCA<\/a>, and runtime testing with <a href=\"https:\/\/checkmarx.com\/learn\/dast\/\">DAST<\/a>.<\/p>\n\n\n\n<p>A combined approach helps teams find issues early (SAST\/SCA), observe behavior in a running app (DAST), and then validate the most critical paths via VAPT.<\/p>\n\n\n\n<p>To go deeper on these methods, see our <a href=\"https:\/\/checkmarx.com\/learn\/sast\/sast-vs-dast\/\">SAST vs. DAST comparison<\/a> and the <a href=\"https:\/\/checkmarx.com\/learn\/sast\/\">SAST Knowledge Hub<\/a> and <a href=\"https:\/\/checkmarx.com\/learn\/dast\/\">DAST Knowledge Hub<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\"><strong>Vulnerability Assessment vs. Penetration Testing (VA vs. PT)<\/strong><\/h2>\n\n\n\n<p><strong>Vulnerability Assessment (VA)<\/strong> uses automated scanners and known vulnerability data to inventory and prioritize weaknesses across assets. <strong>Penetration Testing (PT)<\/strong> applies manual, adversary-like techniques to exploit selected weaknesses, demonstrate impact, and validate what is truly exploitable in context.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Quick comparison:<\/strong><\/h3>\n\n\n\n<p>&#8211; <strong>Primary purpose:<\/strong> VA identifies known weaknesses at scale; PT validates exploitability and real-world impact.<\/p>\n\n\n\n<p>&#8211; <strong>Typical approach:<\/strong> VA relies on automated scanning and configuration checks; PT uses manual testing and controlled exploitation by experts.<\/p>\n\n\n\n<p>&#8211; <strong>Coverage vs. depth:<\/strong> VA offers broad coverage and may include false positives; PT goes deeper on critical paths with fewer false positives.<\/p>\n\n\n\n<p>&#8211; <strong>Output:<\/strong> VA produces a ranked list of vulnerabilities with severity; PT provides evidence-backed findings, exploit paths, and risk scenarios.<\/p>\n\n\n\n<p>&#8211; <strong>Best use:<\/strong> VA for routine visibility and hygiene; PT for assurance, control validation, and compliance testing.<\/p>\n\n\n\n<p>Related reading: <a href=\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessments\/\">Vulnerability Assessments<\/a> and <a href=\"https:\/\/checkmarx.com\/learn\/vulnerability-management\/what-is-vulnerability-management\/\">Vulnerability Management<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\"><strong>VAPT Process: From Scoping to Retesting<\/strong><\/h2>\n\n\n\n<p>1) <strong>Scoping &amp; rules of engagement<\/strong>: Define in-scope apps, APIs, environments, timelines, success criteria, and legal permissions.<\/p>\n\n\n\n<p>2) <strong>Discovery &amp; enumeration<\/strong>: Map assets, tech stacks, and attack surface (hosts, services, endpoints).<\/p>\n\n\n\n<p>3) <strong>Vulnerability assessment<\/strong>: Run authenticated\/unauthenticated scans and configuration checks; enrich with threat intelligence.<\/p>\n\n\n\n<p>4) <strong>Exploitation &amp; post-exploitation (PT):<\/strong> Attempt safe exploitation of priority findings; chain issues to show business impact.<\/p>\n\n\n\n<p>5) <strong>Risk analysis &amp; reporting<\/strong>: Document evidence, likelihood\/impact, affected components, and remediation guidance.<\/p>\n\n\n\n<p>6) <strong>Fix &amp; retest<\/strong>: Remediate, verify fixes, and update residual risk.<\/p>\n\n\n\n<p>Also see: <a href=\"https:\/\/checkmarx.com\/glossary\/security-vulnerability\/\">Security Vulnerability<\/a> and <a href=\"https:\/\/checkmarx.com\/glossary\/application-vulnerability\/\">Application Vulnerability<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">Checklist: <strong>What a VAPT Report Should Include<\/strong>\n<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Executive summary with risk narrative and top findings<\/li>\n\n\n\n<li>Detailed technical findings with evidence (requests\/responses, PoC where appropriate)<\/li>\n\n\n\n<li>Exploit paths, affected assets, and business impact<\/li>\n\n\n\n<li>Clear remediation and mitigation guidance (prioritized)<\/li>\n\n\n\n<li> Methodology, scope, tools, and tester qualifications<\/li>\n\n\n\n<li>Retesting results and closure status<br>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\"><strong>How Often to Run VAPT (and What Compliance Expects)<\/strong><\/h2>\n\n\n\n<p>Run assessments and tests on a regular cadence and after significant changes. Many public-sector and enterprise guidelines emphasize performing both activities throughout delivery\u00e2\u20ac\u201dnot as a one-off pre-release gate.<\/p>\n\n\n\n<p><strong>Tip:<\/strong> Use continuous scanning to maintain visibility and schedule targeted PT to validate your most critical apps and new attack paths. <\/p>\n\n\n\n<p>For payment card environments, penetration testing expectations sit under PCI DSS Requirement 11 (segmentation validation included); organizations targeting ISO\/IEC 27001 should apply testing as part of risk-based control validation and continuous improvement.<\/p>\n\n\n\n<p>Explore dynamic testing options with <a href=\"https:\/\/checkmarx.com\/checkmarx-dast\/\">Checkmarx DAST<\/a>, then complement with developer-first prevention using <a href=\"https:\/\/checkmarx.com\/learn\/sast\/\">SAST<\/a> and <a href=\"https:\/\/checkmarx.com\/glossary\/software-composition-analysis-sca\/\">SCA<\/a>.<\/p>\n\n\n\n<div style=\"height:104px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<section class=\"section-faq js--gsap-faq light-theme\">\n    <div class=\"main-wrapper\">\n        <h2 class=\"section-faq__title js--gsap-faq-title article-anchor\" id=\"article-anchor-6\">VAPT FAQs<\/h2>\n        <ul class=\"section-faq__wrapper js--faq-wrapper\">\n                            <li class=\"section-faq__item js--faq-item js--gsap-faq-item\">\n                    <button class=\"section-faq__btn js--faq-btn\">\n                        <span class=\"section-faq__btn-span\">Is VAPT the same as vulnerability scanning?<\/span>                        <svg viewbox=\"0 0 10 10\" fill=\"none\" class=\"section-faq__btn-icon\" stroke=\"currentColor\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                            <path d=\"M0.40625 5.04883H9.23256\" stroke-width=\"1.52413\"><\/path>\n                            <path d=\"M4.82031 0.632812L4.82031 9.45912\" stroke-width=\"1.52413\"><\/path>\n                        <\/svg>\n                    <\/button>\n                    <p class=\"section-faq__body text_1 js--faq-body\">No. Scanning identifies potential issues at scale; a penetration test validates exploitability and impact. Use both.<\/p>                <\/li>\n                                <li class=\"section-faq__item js--faq-item js--gsap-faq-item\">\n                    <button class=\"section-faq__btn js--faq-btn\">\n                        <span class=\"section-faq__btn-span\">Where does VAPT fit in DevSecOps?<\/span>                        <svg viewbox=\"0 0 10 10\" fill=\"none\" class=\"section-faq__btn-icon\" stroke=\"currentColor\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                            <path d=\"M0.40625 5.04883H9.23256\" stroke-width=\"1.52413\"><\/path>\n                            <path d=\"M4.82031 0.632812L4.82031 9.45912\" stroke-width=\"1.52413\"><\/path>\n                        <\/svg>\n                    <\/button>\n                    <p class=\"section-faq__body text_1 js--faq-body\">Shift left with <a href=\"https:\/\/checkmarx.com\/cxsast-source-code-scanning\/\">SAST<\/a> and <a href=\"https:\/\/checkmarx.com\/cxsca-open-source-scanning\/\">SCA<\/a> to prevent defects in code and dependencies, apply <a href=\"https:\/\/checkmarx.com\/checkmarx-dast\/\">DAST<\/a> for runtime coverage, and use VAPT to validate what really matters before (and after) release.<\/p>                <\/li>\n                                <li class=\"section-faq__item js--faq-item js--gsap-faq-item\">\n                    <button class=\"section-faq__btn js--faq-btn\">\n                        <span class=\"section-faq__btn-span\">What\u2019s the deliverable?<\/span>                        <svg viewbox=\"0 0 10 10\" fill=\"none\" class=\"section-faq__btn-icon\" stroke=\"currentColor\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                            <path d=\"M0.40625 5.04883H9.23256\" stroke-width=\"1.52413\"><\/path>\n                            <path d=\"M4.82031 0.632812L4.82031 9.45912\" stroke-width=\"1.52413\"><\/path>\n                        <\/svg>\n                    <\/button>\n                    <p class=\"section-faq__body text_1 js--faq-body\">An evidence\u2011based report with prioritized findings, exploit paths, and actionable fixes &#8211; plus retest results confirming remediation.<\/p>                <\/li>\n                        <\/ul>\n    <\/div>\n<\/section>\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"url\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Is VAPT the same as vulnerability scanning?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. Scanning identifies potential issues at scale; a penetration test validates exploitability and impact. Use both.\"}},{\"@type\":\"Question\",\"name\":\"Where does VAPT fit in DevSecOps?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Shift left with SAST and SCA to prevent defects in code and dependencies, apply DAST for runtime coverage, and use VAPT to validate what really matters before (and after) release.\"}},{\"@type\":\"Question\",\"name\":\"What\u2019s the deliverable?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"An evidence\u2011based report with prioritized findings, exploit paths, and actionable fixes - plus retest results confirming remediation.\"}}]}<\/script>","protected":false},"excerpt":{"rendered":"<p>VAPT combines two complementary practices: a vulnerability assessment to identify known weaknesses at scale and a penetration test to safely exploit and validate real-world impact. Together, they give teams a prioritized view of risk and help prove which findings truly matter. VAPT in AppSec: Where It Fits VAPT is typically performed against running systems, apps, [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":103093,"template":"","glossary-tags":[6,9,1436],"class_list":["post-53379","glossary","type-glossary","status-publish","has-post-thumbnail","hentry","glossary-tags-application-security-testing","glossary-tags-dast","glossary-tags-sast"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>VAPT: Vulnerability Assessment &amp; Penetration Testing (Definition) | Checkmarx<\/title>\n<meta name=\"description\" content=\"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VAPT: Vulnerability Assessment &amp; Penetration Testing (Definition) | Checkmarx\" \/>\n<meta property=\"og:description\" content=\"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-13T20:57:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2033\" \/>\n\t<meta property=\"og:image:height\" content=\"1017\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\",\"url\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\",\"name\":\"VAPT: Vulnerability Assessment & Penetration Testing (Definition) | Checkmarx\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp\",\"datePublished\":\"2014-05-19T14:18:58+00:00\",\"dateModified\":\"2026-04-13T20:57:56+00:00\",\"description\":\"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.\",\"breadcrumb\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp\",\"width\":2033,\"height\":1017,\"caption\":\"The best DAST tools enhance SAST and SDA\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Glossary\",\"item\":\"https:\/\/checkmarx.com\/glossary\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Is VAPT (Vulnerability Assessment &amp; Penetration Testing)?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"VAPT: Vulnerability Assessment & Penetration Testing (Definition) | Checkmarx","description":"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/","og_locale":"en_US","og_type":"article","og_title":"VAPT: Vulnerability Assessment & Penetration Testing (Definition) | Checkmarx","og_description":"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.","og_url":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2026-04-13T20:57:56+00:00","og_image":[{"width":2033,"height":1017,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/","url":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/","name":"VAPT: Vulnerability Assessment & Penetration Testing (Definition) | Checkmarx","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp","datePublished":"2014-05-19T14:18:58+00:00","dateModified":"2026-04-13T20:57:56+00:00","description":"Learn what VAPT is, the difference between vulnerability assessment and penetration testing, core steps, deliverables, and how VAPT fits with SAST\/DAST.","breadcrumb":{"@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/08\/DAST-for-Modern-Apps.webp","width":2033,"height":1017,"caption":"The best DAST tools enhance SAST and SDA"},{"@type":"BreadcrumbList","@id":"https:\/\/checkmarx.com\/glossary\/vulnerability-assessment-and-penetration-testing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Glossary","item":"https:\/\/checkmarx.com\/glossary\/"},{"@type":"ListItem","position":2,"name":"What Is VAPT (Vulnerability Assessment &amp; Penetration Testing)?"}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53379","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53379\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/103093"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=53379"}],"wp:term":[{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary-tags?post=53379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}