
Baidu was tested and 103 issues were detected across the site. The most critical finding was: Analytics requests leak login state via isLogin parameter. Issues span Security, Legal, A11y, Performance categories. Persona feedback rated Visual highest (8/10) and Accessibility lowest (6/10).







isLogin=0 observed in sp1.baidu.com/v.gif requestsGET https://sp1.baidu.com/-L-Xsjip0QIZ8tyhnq/v.gif?logactid=1234567890&showTab=10000&opType=showpv&mod=superman%3Alib&submod=index&superver=supernewplus&glogid=2151366034&type=2011&pid=315&isLogin=0&version=PCHome&terminal=PC&...&from_login=&from_reg=&query=&curcard=2POST https://mbd.baidu.com/ztbox?action=zpblog&appname=pcsearch&sid=63146_67721_67861_67885_67891_67942_67966_68042_67984_68002_68133_68142_68149_68152_68140_68189_68227_68263_68287_68288_68297_68309_68347_68369_68354_68433_68454_68441_68513_68529_68543_68551_68508_68517&v=2.0&data=%7B%22cateid%22%3A%2299%22%2C%22actiondata%22%3A%7B%22id%22%3A18463%2C%22type%22%3A%220%22%2C%22timestamp%22%3A1774518421029%2C%22content%22%3A%7B%22page%22%3A%22home%22%2C%22source%22%3A%22%22%2C%22from%22%3A%22search%22%2C%22type%22%3A%22display%22%2C%22value%22%3A%22%22%2C%22ext%22%3A%7B%22status%22%3A%22default%22%2C%22is_log%22%3A%220%22%2C%22have_hotsearch%22%3A%221%22%2C%22is_kuang_rec_disp%22%3A%221%22%2C%22search_kuang_status%22%3A%22default%22%2C%22aisou_btn%22%3A%220%22%2C%22kuang_rec_status%22%3A%221%22%7D%7D%7D%7DGET http://www.baidu.com/more - Status: 307; GET http://www.baidu.com/more/ - Status: 307