Inspect scripts, templates, and raw server-side controllers to scan for SQL Injection, XSS, prototype pollution, and dangerous evaluations.
Load sample snippets containing security exploits to test scanner heuristics: