One real vulnerability. One scary-looking false positive.
Can you tell which is which?

Ten small AppSec cases. Seven have a real defect. Three do not — and all three are written to look like exactly what a scanner flags. Getting a decoy wrong costs the same as missing a real bug, because in a real queue it does.

No signup, nothing stored, nothing sent anywhere. About five minutes.