Bug bounty results prove real-world depth. Juice Shop proves that the same SecHive reporting style can be inspected end to end on a safe, intentionally vulnerable target. Routes, payloads, source references and evidence snippets are retained.
The Juice Shop source defines 111 challenges. SecHive findings are not the same object as scoreboard unlocks; we report challenge-equivalent coverage for sizing the gap.
| Run style | Covered | Gap | Notes |
|---|---|---|---|
| Latest live runtime | 35 / 111 | 76 | Runtime findings backed by live target behavior and evidence artifacts. |
| Latest source-aware | 58 / 111 | 53 | 35 runtime findings + 23 source-analysis candidates + 2 source-review candidates. |
| Archived black-box reference | 32 / 111 | 79 | Earlier public report retained for reproducibility. |
| Archived white-box reference | 55 / 111 | 56 | Source-candidate separation kept for audit trail. |
The bug bounty corpus is redacted because it comes from live programs. Juice Shop is an intentionally vulnerable benchmark, so routes, payloads, source references, evidence snippets and remediation notes remain intact in the published report.