SiteShadow
Back to vulnerability library
Detected byStatic analysis

MFA01 MFA Not Enforced

What this means

SiteShadow flagged flows where MFA is missing, optional, or can be bypassed for accounts/actions that should require it (admin actions, billing, API key management).

Why it matters

Safer examples

1) Require MFA for admins and high-risk actions

Examples: billing changes, payouts, role changes, API key creation, SSO changes.

2) Use step-up authentication

Even if a user is logged in, require MFA re-check for sensitive operations.

3) Make recovery safe

Use recovery codes, secure device enrollment, and strong support verification to avoid MFA bypass via support.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.