Autocomplete enables in login form


In most web browsers, a user can save the username and password entered in HTML forms.

Bussines Impact

Some data that is submitted in forms could contain sensitive information (for example, credit card security code).

As a website author, you might prefer that the browser not remember the values for such fields, even if the browser’s autocomplete feature is enabled.

an attacker who found vulnerabilities in applications related to this site, such as Cross-Site Scripting, could exploit it to recover browser credentials.


Make sure to add to the form autocomplete=”off” to prevent this finding from happening in the future.

More Details

This function can be defined by the user as well as by applications that use user credentials. If the function is enabled, the user credentials will be saved on the local server and can be retrieved by the attacker.


