I read that ESAPI is included as part of WCS. Are all the OWSAP security threats by default handled? Where can i get additional information about this? Also, are there any specific guidelines for performing penetration test on end sites developed using webcenter sites?