4
Critical
2
High
25
Medium
66
Low
7
Info
Security Findings (104)
No findings match the current filter.
| # | Severity | Module | Finding | Timestamp |
|---|---|---|---|---|
| 1 | INFO | INIT | Audit started against https://example.com Resolved IP: 104.18.27.120 | Mode: NORMAL |
2026-03-23T15:15:36Z |
| 2 | INFO | RECON | WHOIS data collected for example.com Registrar: N/A | Expiry: 2026-08-13 |
2026-03-23T15:15:36Z |
| 3 | INFO | RECON | Subdomain enumeration: 37616 hosts discovered 0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com /root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt |
2026-03-23T15:16:22Z |
| 4 | INFO | FINGERPRINT | WAF detected: Cloudflare (Cloudflare Inc.) WAF. The target appears to be protected by a Web Application Firewall. Cloudflare (Cloudflare Inc.) WAF. |
2026-03-23T15:16:25Z |
| 5 | LOW | FINGERPRINT | Version disclosure via 'Server' header The server reveals technology/version info in response headers. Remove or neutralise the 'Server' header in your web server configuration. |
2026-03-23T15:16:25Z |
| 6 | LOW | SSL | testssl: [TLS1] offered (deprecated) Refer to testssl documentation for TLS1 |
2026-03-23T15:19:44Z |
| 7 | LOW | SSL | testssl: [TLS1_1] offered (deprecated) Refer to testssl documentation for TLS1_1 |
2026-03-23T15:19:44Z |
| 8 | MEDIUM | SSL | testssl: [cipherlist_3DES_IDEA] offered Refer to testssl documentation for cipherlist_3DES_IDEA |
2026-03-23T15:19:44Z |
| 9 | LOW | SSL | testssl: [cipherlist_OBSOLETED] offered Refer to testssl documentation for cipherlist_OBSOLETED |
2026-03-23T15:19:44Z |
| 10 | LOW | SSL | testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_xc013 |
2026-03-23T15:19:44Z |
| 11 | LOW | SSL | testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_x2f |
2026-03-23T15:19:44Z |
| 12 | LOW | SSL | testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_xc014 |
2026-03-23T15:19:44Z |
| 13 | LOW | SSL | testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_x35 |
2026-03-23T15:19:44Z |
| 14 | MEDIUM | SSL | testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA Refer to testssl documentation for cipher-tls1_x0a |
2026-03-23T15:19:44Z |
| 15 | LOW | SSL | testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_1_xc013 |
2026-03-23T15:19:44Z |
| 16 | LOW | SSL | testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_1_x2f |
2026-03-23T15:19:44Z |
| 17 | LOW | SSL | testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_1_xc014 |
2026-03-23T15:19:44Z |
| 18 | LOW | SSL | testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_1_x35 |
2026-03-23T15:19:44Z |
| 19 | LOW | SSL | testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc009 |
2026-03-23T15:19:44Z |
| 20 | LOW | SSL | testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc00a |
2026-03-23T15:19:44Z |
| 21 | LOW | SSL | testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc023 |
2026-03-23T15:19:44Z |
| 22 | LOW | SSL | testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc024 |
2026-03-23T15:19:44Z |
| 23 | LOW | SSL | testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc013 |
2026-03-23T15:19:45Z |
| 24 | LOW | SSL | testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_x2f |
2026-03-23T15:19:45Z |
| 25 | LOW | SSL | testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc014 |
2026-03-23T15:19:45Z |
| 26 | LOW | SSL | testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_x35 |
2026-03-23T15:19:45Z |
| 27 | LOW | SSL | testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25 Refer to testssl documentation for cipher-tls1_2_xc027 |
2026-03-23T15:19:45Z |
| 28 | LOW | SSL | testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256 Refer to testssl documentation for cipher-tls1_2_x3c |
2026-03-23T15:19:45Z |
| 29 | LOW | SSL | testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38 Refer to testssl documentation for cipher-tls1_2_xc028 |
2026-03-23T15:19:45Z |
| 30 | LOW | SSL | testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256 Refer to testssl documentation for cipher-tls1_2_x3d |
2026-03-23T15:19:45Z |
| 31 | HIGH | SSL | testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature' Refer to testssl documentation for cert_keyUsage <hostCert#1> |
2026-03-23T15:19:45Z |
| 32 | CRITICAL | SSL | testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Refer to testssl documentation for cert_chain_of_trust <hostCert#1> |
2026-03-23T15:19:45Z |
| 33 | MEDIUM | SSL | testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52) Refer to testssl documentation for cert_expirationStatus <hostCert#1> |
2026-03-23T15:19:45Z |
| 34 | MEDIUM | SSL | testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57 Refer to testssl documentation for cert_notAfter <hostCert#1> |
2026-03-23T15:19:45Z |
| 35 | LOW | SSL | testssl: [DNS_CAArecord <hostCert#1>] -- Refer to testssl documentation for DNS_CAArecord <hostCert#1> |
2026-03-23T15:19:45Z |
| 36 | CRITICAL | SSL | testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Refer to testssl documentation for cert_chain_of_trust <hostCert#2> |
2026-03-23T15:19:45Z |
| 37 | MEDIUM | SSL | testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52) Refer to testssl documentation for cert_expirationStatus <hostCert#2> |
2026-03-23T15:19:45Z |
| 38 | MEDIUM | SSL | testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57 Refer to testssl documentation for cert_notAfter <hostCert#2> |
2026-03-23T15:19:45Z |
| 39 | LOW | SSL | testssl: [DNS_CAArecord <hostCert#2>] -- Refer to testssl documentation for DNS_CAArecord <hostCert#2> |
2026-03-23T15:19:45Z |
| 40 | LOW | SSL | testssl: [HSTS] not offered Refer to testssl documentation for HSTS |
2026-03-23T15:19:46Z |
| 41 | MEDIUM | SSL | testssl: [security_headers] -- Refer to testssl documentation for security_headers |
2026-03-23T15:19:46Z |
| 42 | MEDIUM | SSL | testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested Refer to testssl documentation for BREACH |
2026-03-23T15:19:46Z |
| 43 | LOW | SSL | testssl: [SWEET32] uses 64 bit block ciphers Refer to testssl documentation for SWEET32 |
2026-03-23T15:19:46Z |
| 44 | MEDIUM | SSL | testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA Refer to testssl documentation for BEAST_CBC_TLS1 |
2026-03-23T15:19:46Z |
| 45 | LOW | SSL | testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated) Refer to testssl documentation for BEAST |
2026-03-23T15:19:46Z |
| 46 | LOW | SSL | testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers Refer to testssl documentation for LUCKY13 |
2026-03-23T15:19:46Z |
| 47 | MEDIUM | SSL | testssl: [overall_grade] B Refer to testssl documentation for overall_grade |
2026-03-23T15:19:46Z |
| 48 | LOW | SSL | testssl: [TLS1] offered (deprecated) Refer to testssl documentation for TLS1 |
2026-03-23T15:19:46Z |
| 49 | LOW | SSL | testssl: [TLS1_1] offered (deprecated) Refer to testssl documentation for TLS1_1 |
2026-03-23T15:19:46Z |
| 50 | MEDIUM | SSL | testssl: [cipherlist_3DES_IDEA] offered Refer to testssl documentation for cipherlist_3DES_IDEA |
2026-03-23T15:19:46Z |
| 51 | LOW | SSL | testssl: [cipherlist_OBSOLETED] offered Refer to testssl documentation for cipherlist_OBSOLETED |
2026-03-23T15:19:46Z |
| 52 | LOW | SSL | testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_xc013 |
2026-03-23T15:19:46Z |
| 53 | LOW | SSL | testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_x2f |
2026-03-23T15:19:46Z |
| 54 | LOW | SSL | testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_xc014 |
2026-03-23T15:19:46Z |
| 55 | LOW | SSL | testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_x35 |
2026-03-23T15:19:46Z |
| 56 | MEDIUM | SSL | testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA Refer to testssl documentation for cipher-tls1_x0a |
2026-03-23T15:19:46Z |
| 57 | LOW | SSL | testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_1_xc013 |
2026-03-23T15:19:47Z |
| 58 | LOW | SSL | testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_1_x2f |
2026-03-23T15:19:47Z |
| 59 | LOW | SSL | testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_1_xc014 |
2026-03-23T15:19:47Z |
| 60 | LOW | SSL | testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_1_x35 |
2026-03-23T15:19:47Z |
| 61 | LOW | SSL | testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc009 |
2026-03-23T15:19:47Z |
| 62 | LOW | SSL | testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc00a |
2026-03-23T15:19:47Z |
| 63 | LOW | SSL | testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc023 |
2026-03-23T15:19:47Z |
| 64 | LOW | SSL | testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc024 |
2026-03-23T15:19:47Z |
| 65 | LOW | SSL | testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc013 |
2026-03-23T15:19:47Z |
| 66 | LOW | SSL | testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Refer to testssl documentation for cipher-tls1_2_x2f |
2026-03-23T15:19:47Z |
| 67 | LOW | SSL | testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_xc014 |
2026-03-23T15:19:47Z |
| 68 | LOW | SSL | testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Refer to testssl documentation for cipher-tls1_2_x35 |
2026-03-23T15:19:47Z |
| 69 | LOW | SSL | testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25 Refer to testssl documentation for cipher-tls1_2_xc027 |
2026-03-23T15:19:47Z |
| 70 | LOW | SSL | testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256 Refer to testssl documentation for cipher-tls1_2_x3c |
2026-03-23T15:19:47Z |
| 71 | LOW | SSL | testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38 Refer to testssl documentation for cipher-tls1_2_xc028 |
2026-03-23T15:19:47Z |
| 72 | LOW | SSL | testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256 Refer to testssl documentation for cipher-tls1_2_x3d |
2026-03-23T15:19:47Z |
| 73 | HIGH | SSL | testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature' Refer to testssl documentation for cert_keyUsage <hostCert#1> |
2026-03-23T15:19:47Z |
| 74 | CRITICAL | SSL | testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Refer to testssl documentation for cert_chain_of_trust <hostCert#1> |
2026-03-23T15:19:47Z |
| 75 | MEDIUM | SSL | testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52) Refer to testssl documentation for cert_expirationStatus <hostCert#1> |
2026-03-23T15:19:47Z |
| 76 | MEDIUM | SSL | testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57 Refer to testssl documentation for cert_notAfter <hostCert#1> |
2026-03-23T15:19:48Z |
| 77 | LOW | SSL | testssl: [DNS_CAArecord <hostCert#1>] -- Refer to testssl documentation for DNS_CAArecord <hostCert#1> |
2026-03-23T15:19:48Z |
| 78 | CRITICAL | SSL | testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Refer to testssl documentation for cert_chain_of_trust <hostCert#2> |
2026-03-23T15:19:48Z |
| 79 | MEDIUM | SSL | testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52) Refer to testssl documentation for cert_expirationStatus <hostCert#2> |
2026-03-23T15:19:48Z |
| 80 | MEDIUM | SSL | testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57 Refer to testssl documentation for cert_notAfter <hostCert#2> |
2026-03-23T15:19:48Z |
| 81 | LOW | SSL | testssl: [DNS_CAArecord <hostCert#2>] -- Refer to testssl documentation for DNS_CAArecord <hostCert#2> |
2026-03-23T15:19:48Z |
| 82 | LOW | SSL | testssl: [HSTS] not offered Refer to testssl documentation for HSTS |
2026-03-23T15:19:48Z |
| 83 | MEDIUM | SSL | testssl: [security_headers] -- Refer to testssl documentation for security_headers |
2026-03-23T15:19:48Z |
| 84 | MEDIUM | SSL | testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested Refer to testssl documentation for BREACH |
2026-03-23T15:19:48Z |
| 85 | LOW | SSL | testssl: [SWEET32] uses 64 bit block ciphers Refer to testssl documentation for SWEET32 |
2026-03-23T15:19:48Z |
| 86 | MEDIUM | SSL | testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA Refer to testssl documentation for BEAST_CBC_TLS1 |
2026-03-23T15:19:48Z |
| 87 | LOW | SSL | testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated) Refer to testssl documentation for BEAST |
2026-03-23T15:19:48Z |
| 88 | LOW | SSL | testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers Refer to testssl documentation for LUCKY13 |
2026-03-23T15:19:48Z |
| 89 | MEDIUM | SSL | testssl: [overall_grade] B Refer to testssl documentation for overall_grade |
2026-03-23T15:19:48Z |
| 90 | MEDIUM | SSL | Certificate expires in 52 days May 14 18:57:50 2026 GMT Plan certificate renewal. |
2026-03-23T15:19:48Z |
| 91 | MEDIUM | SSL | HSTS header not configured Strict-Transport-Security is absent β browsers may access the site over HTTP. Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload |
2026-03-23T15:19:49Z |
| 92 | LOW | HEADERS | Permissions-Policy missing The response is missing the 'permissions-policy' security header. Add: Permissions-Policy: geolocation=(), microphone=(), camera=() |
2026-03-23T15:19:49Z |
| 93 | LOW | HEADERS | Cross-Origin-Resource-Policy (CORP) missing The response is missing the 'cross-origin-resource-policy' security header. Add: Cross-Origin-Resource-Policy: same-origin |
2026-03-23T15:19:49Z |
| 94 | LOW | HEADERS | Cross-Origin-Opener-Policy (COOP) missing The response is missing the 'cross-origin-opener-policy' security header. Add: Cross-Origin-Opener-Policy: same-origin |
2026-03-23T15:19:49Z |
| 95 | LOW | HEADERS | X-Content-Type-Options missing β MIME sniffing risk The response is missing the 'x-content-type-options' security header. Add: X-Content-Type-Options: nosniff |
2026-03-23T15:19:49Z |
| 96 | MEDIUM | HEADERS | X-Frame-Options missing β clickjacking risk The response is missing the 'x-frame-options' security header. Add: X-Frame-Options: SAMEORIGIN |
2026-03-23T15:19:49Z |
| 97 | MEDIUM | HEADERS | Content-Security-Policy (CSP) missing The response is missing the 'content-security-policy' security header. Implement a strict CSP to mitigate XSS and data injection attacks. |
2026-03-23T15:19:49Z |
| 98 | LOW | HEADERS | Referrer-Policy missing The response is missing the 'referrer-policy' security header. Add: Referrer-Policy: strict-origin-when-cross-origin |
2026-03-23T15:19:49Z |
| 99 | LOW | HEADERS | Informative header exposed: Server Server reveals technology details via 'Server' header. server: clo Remove or anonymise the 'Server' header in your server configuration. |
2026-03-23T15:19:49Z |
| 100 | MEDIUM | HEADERS | HTTP does not redirect to HTTPS (HTTP 200) Requests over HTTP are not automatically upgraded to HTTPS. http://example.com β 200 Configure a permanent 301 redirect from HTTP to HTTPS. |
2026-03-23T15:19:49Z |
| 101 | LOW | HEADERS | Cache-Control header missing Without Cache-Control, sensitive pages may be cached by intermediaries. Add: Cache-Control: no-store, no-cache on authenticated/sensitive pages. |
2026-03-23T15:19:49Z |
| 102 | INFO | SQLI | No obvious SQLi on primary URL Manual testing with specific parameters recommended. |
2026-03-23T15:20:05Z |
| 103 | INFO | CMS | CMS detected: unknown | 2026-03-23T15:21:12Z |
| 104 | INFO | SSRF | No in-band SSRF detected on common parameters Out-of-band (OOB) SSRF may still exist. Use Burp Collaborator or Interactsh for blind testing. |
2026-03-23T15:26:05Z |