Pusaka Super Apps is an integrated digital platform owned by the Ministry of Religious Affairs of the Republic of Indonesia (Kemenag) that provides various religious services for millions of users. Along with the increasing reliance on government digital services, threats to information system security are becoming more complex. This study conducts a security assessment of the Pusaka Super Apps web application ( https://pusaka-v3.kemenag.go.id ) using two complementary frameworks, namely OWASP Top 10 2025 and the Information Systems Security Assessment Framework (ISSAF). The research method is qualitative descriptive with black-box testing and gray-box testing approaches that include the stages of reconnaissance, scanning, enumeration, vulnerability assessment, and impact analysis. The results of the study identified several medium vulnerabilities, including Content Security Policy Header Not Set, Missing Anti-clickjacking Header, and Missing Sub Resource Integrity Attribute. This study provides structured remediation recommendations and serves as a contribution to efforts in strengthening cyber security for government applications in Indonesia.
Copyrights © 2026