Details.
Complete source code analysis includes an automated review and a manual inspection of sensitive code portions, adding a business logic perspective that is not accessible to a machine. The review particularly examines authentication, session management, access rights and form processing. Code reviews follow the OWASP standard.
