Tests authorized running web apps and APIs for reproducible vulnerabilities, with optional source access. Use for application pentests; excludes source-only audits, design reviews and applying fixes.