WebSec-Audit β€” Security Report

https://example.com  |  2026-03-23 16:15:31  |  v1.0.1 by davidalvarezp
CRITICAL RISK
4
Critical
2
High
25
Medium
66
Low
7
Info

Scan Metadata

Target https://example.com Domain example.com IP 104.18.27.120 Date 2026-03-23 16:15:31 Duration 1541s Auditor root@debian12 Mode NORMAL

Module Status

Recon βœ” enabled Port Scan βœ” enabled SSL/TLS βœ” enabled Headers βœ” enabled Dir Brute βœ” enabled SQLi / XSS βœ” / βœ” CMS βœ” enabled Nuclei βœ” enabled

Security Findings (104)

No findings match the current filter.
# Severity Module Finding Timestamp
1 INFO INIT Audit started against https://example.com
Resolved IP: 104.18.27.120 | Mode: NORMAL
2026-03-23T15:15:36Z
2 INFO RECON WHOIS data collected for example.com
Registrar: N/A | Expiry: 2026-08-13
2026-03-23T15:15:36Z
3 INFO RECON Subdomain enumeration: 37616 hosts discovered
0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com
/root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt
2026-03-23T15:16:22Z
4 INFO FINGERPRINT WAF detected: Cloudflare (Cloudflare Inc.) WAF.
The target appears to be protected by a Web Application Firewall.
Cloudflare (Cloudflare Inc.) WAF.
2026-03-23T15:16:25Z
5 LOW FINGERPRINT Version disclosure via 'Server' header
The server reveals technology/version info in response headers.
Remove or neutralise the 'Server' header in your web server configuration.
2026-03-23T15:16:25Z
6 LOW SSL testssl: [TLS1] offered (deprecated)
Refer to testssl documentation for TLS1
2026-03-23T15:19:44Z
7 LOW SSL testssl: [TLS1_1] offered (deprecated)
Refer to testssl documentation for TLS1_1
2026-03-23T15:19:44Z
8 MEDIUM SSL testssl: [cipherlist_3DES_IDEA] offered
Refer to testssl documentation for cipherlist_3DES_IDEA
2026-03-23T15:19:44Z
9 LOW SSL testssl: [cipherlist_OBSOLETED] offered
Refer to testssl documentation for cipherlist_OBSOLETED
2026-03-23T15:19:44Z
10 LOW SSL testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc013
2026-03-23T15:19:44Z
11 LOW SSL testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_x2f
2026-03-23T15:19:44Z
12 LOW SSL testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc014
2026-03-23T15:19:44Z
13 LOW SSL testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_x35
2026-03-23T15:19:44Z
14 MEDIUM SSL testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA
Refer to testssl documentation for cipher-tls1_x0a
2026-03-23T15:19:44Z
15 LOW SSL testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc013
2026-03-23T15:19:44Z
16 LOW SSL testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x2f
2026-03-23T15:19:44Z
17 LOW SSL testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc014
2026-03-23T15:19:44Z
18 LOW SSL testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x35
2026-03-23T15:19:44Z
19 LOW SSL testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc009
2026-03-23T15:19:44Z
20 LOW SSL testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc00a
2026-03-23T15:19:44Z
21 LOW SSL testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc023
2026-03-23T15:19:44Z
22 LOW SSL testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc024
2026-03-23T15:19:44Z
23 LOW SSL testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc013
2026-03-23T15:19:45Z
24 LOW SSL testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x2f
2026-03-23T15:19:45Z
25 LOW SSL testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc014
2026-03-23T15:19:45Z
26 LOW SSL testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x35
2026-03-23T15:19:45Z
27 LOW SSL testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25
Refer to testssl documentation for cipher-tls1_2_xc027
2026-03-23T15:19:45Z
28 LOW SSL testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3c
2026-03-23T15:19:45Z
29 LOW SSL testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38
Refer to testssl documentation for cipher-tls1_2_xc028
2026-03-23T15:19:45Z
30 LOW SSL testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3d
2026-03-23T15:19:45Z
31 HIGH SSL testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'
Refer to testssl documentation for cert_keyUsage <hostCert#1>
2026-03-23T15:19:45Z
32 CRITICAL SSL testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#1>
2026-03-23T15:19:45Z
33 MEDIUM SSL testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#1>
2026-03-23T15:19:45Z
34 MEDIUM SSL testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#1>
2026-03-23T15:19:45Z
35 LOW SSL testssl: [DNS_CAArecord <hostCert#1>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#1>
2026-03-23T15:19:45Z
36 CRITICAL SSL testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#2>
2026-03-23T15:19:45Z
37 MEDIUM SSL testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#2>
2026-03-23T15:19:45Z
38 MEDIUM SSL testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#2>
2026-03-23T15:19:45Z
39 LOW SSL testssl: [DNS_CAArecord <hostCert#2>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#2>
2026-03-23T15:19:45Z
40 LOW SSL testssl: [HSTS] not offered
Refer to testssl documentation for HSTS
2026-03-23T15:19:46Z
41 MEDIUM SSL testssl: [security_headers] --
Refer to testssl documentation for security_headers
2026-03-23T15:19:46Z
42 MEDIUM SSL testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested
Refer to testssl documentation for BREACH
2026-03-23T15:19:46Z
43 LOW SSL testssl: [SWEET32] uses 64 bit block ciphers
Refer to testssl documentation for SWEET32
2026-03-23T15:19:46Z
44 MEDIUM SSL testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA
Refer to testssl documentation for BEAST_CBC_TLS1
2026-03-23T15:19:46Z
45 LOW SSL testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
Refer to testssl documentation for BEAST
2026-03-23T15:19:46Z
46 LOW SSL testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers
Refer to testssl documentation for LUCKY13
2026-03-23T15:19:46Z
47 MEDIUM SSL testssl: [overall_grade] B
Refer to testssl documentation for overall_grade
2026-03-23T15:19:46Z
48 LOW SSL testssl: [TLS1] offered (deprecated)
Refer to testssl documentation for TLS1
2026-03-23T15:19:46Z
49 LOW SSL testssl: [TLS1_1] offered (deprecated)
Refer to testssl documentation for TLS1_1
2026-03-23T15:19:46Z
50 MEDIUM SSL testssl: [cipherlist_3DES_IDEA] offered
Refer to testssl documentation for cipherlist_3DES_IDEA
2026-03-23T15:19:46Z
51 LOW SSL testssl: [cipherlist_OBSOLETED] offered
Refer to testssl documentation for cipherlist_OBSOLETED
2026-03-23T15:19:46Z
52 LOW SSL testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc013
2026-03-23T15:19:46Z
53 LOW SSL testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_x2f
2026-03-23T15:19:46Z
54 LOW SSL testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc014
2026-03-23T15:19:46Z
55 LOW SSL testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_x35
2026-03-23T15:19:46Z
56 MEDIUM SSL testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA
Refer to testssl documentation for cipher-tls1_x0a
2026-03-23T15:19:46Z
57 LOW SSL testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc013
2026-03-23T15:19:47Z
58 LOW SSL testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x2f
2026-03-23T15:19:47Z
59 LOW SSL testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc014
2026-03-23T15:19:47Z
60 LOW SSL testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x35
2026-03-23T15:19:47Z
61 LOW SSL testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc009
2026-03-23T15:19:47Z
62 LOW SSL testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc00a
2026-03-23T15:19:47Z
63 LOW SSL testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc023
2026-03-23T15:19:47Z
64 LOW SSL testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc024
2026-03-23T15:19:47Z
65 LOW SSL testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc013
2026-03-23T15:19:47Z
66 LOW SSL testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x2f
2026-03-23T15:19:47Z
67 LOW SSL testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc014
2026-03-23T15:19:47Z
68 LOW SSL testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x35
2026-03-23T15:19:47Z
69 LOW SSL testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25
Refer to testssl documentation for cipher-tls1_2_xc027
2026-03-23T15:19:47Z
70 LOW SSL testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3c
2026-03-23T15:19:47Z
71 LOW SSL testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38
Refer to testssl documentation for cipher-tls1_2_xc028
2026-03-23T15:19:47Z
72 LOW SSL testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3d
2026-03-23T15:19:47Z
73 HIGH SSL testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'
Refer to testssl documentation for cert_keyUsage <hostCert#1>
2026-03-23T15:19:47Z
74 CRITICAL SSL testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#1>
2026-03-23T15:19:47Z
75 MEDIUM SSL testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#1>
2026-03-23T15:19:47Z
76 MEDIUM SSL testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#1>
2026-03-23T15:19:48Z
77 LOW SSL testssl: [DNS_CAArecord <hostCert#1>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#1>
2026-03-23T15:19:48Z
78 CRITICAL SSL testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#2>
2026-03-23T15:19:48Z
79 MEDIUM SSL testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#2>
2026-03-23T15:19:48Z
80 MEDIUM SSL testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#2>
2026-03-23T15:19:48Z
81 LOW SSL testssl: [DNS_CAArecord <hostCert#2>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#2>
2026-03-23T15:19:48Z
82 LOW SSL testssl: [HSTS] not offered
Refer to testssl documentation for HSTS
2026-03-23T15:19:48Z
83 MEDIUM SSL testssl: [security_headers] --
Refer to testssl documentation for security_headers
2026-03-23T15:19:48Z
84 MEDIUM SSL testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested
Refer to testssl documentation for BREACH
2026-03-23T15:19:48Z
85 LOW SSL testssl: [SWEET32] uses 64 bit block ciphers
Refer to testssl documentation for SWEET32
2026-03-23T15:19:48Z
86 MEDIUM SSL testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA
Refer to testssl documentation for BEAST_CBC_TLS1
2026-03-23T15:19:48Z
87 LOW SSL testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
Refer to testssl documentation for BEAST
2026-03-23T15:19:48Z
88 LOW SSL testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers
Refer to testssl documentation for LUCKY13
2026-03-23T15:19:48Z
89 MEDIUM SSL testssl: [overall_grade] B
Refer to testssl documentation for overall_grade
2026-03-23T15:19:48Z
90 MEDIUM SSL Certificate expires in 52 days
May 14 18:57:50 2026 GMT
Plan certificate renewal.
2026-03-23T15:19:48Z
91 MEDIUM SSL HSTS header not configured
Strict-Transport-Security is absent β€” browsers may access the site over HTTP.
Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
2026-03-23T15:19:49Z
92 LOW HEADERS Permissions-Policy missing
The response is missing the 'permissions-policy' security header.
Add: Permissions-Policy: geolocation=(), microphone=(), camera=()
2026-03-23T15:19:49Z
93 LOW HEADERS Cross-Origin-Resource-Policy (CORP) missing
The response is missing the 'cross-origin-resource-policy' security header.
Add: Cross-Origin-Resource-Policy: same-origin
2026-03-23T15:19:49Z
94 LOW HEADERS Cross-Origin-Opener-Policy (COOP) missing
The response is missing the 'cross-origin-opener-policy' security header.
Add: Cross-Origin-Opener-Policy: same-origin
2026-03-23T15:19:49Z
95 LOW HEADERS X-Content-Type-Options missing β€” MIME sniffing risk
The response is missing the 'x-content-type-options' security header.
Add: X-Content-Type-Options: nosniff
2026-03-23T15:19:49Z
96 MEDIUM HEADERS X-Frame-Options missing β€” clickjacking risk
The response is missing the 'x-frame-options' security header.
Add: X-Frame-Options: SAMEORIGIN
2026-03-23T15:19:49Z
97 MEDIUM HEADERS Content-Security-Policy (CSP) missing
The response is missing the 'content-security-policy' security header.
Implement a strict CSP to mitigate XSS and data injection attacks.
2026-03-23T15:19:49Z
98 LOW HEADERS Referrer-Policy missing
The response is missing the 'referrer-policy' security header.
Add: Referrer-Policy: strict-origin-when-cross-origin
2026-03-23T15:19:49Z
99 LOW HEADERS Informative header exposed: Server
Server reveals technology details via 'Server' header.
server: clo
Remove or anonymise the 'Server' header in your server configuration.
2026-03-23T15:19:49Z
100 MEDIUM HEADERS HTTP does not redirect to HTTPS (HTTP 200)
Requests over HTTP are not automatically upgraded to HTTPS.
http://example.com β†’ 200
Configure a permanent 301 redirect from HTTP to HTTPS.
2026-03-23T15:19:49Z
101 LOW HEADERS Cache-Control header missing
Without Cache-Control, sensitive pages may be cached by intermediaries.
Add: Cache-Control: no-store, no-cache on authenticated/sensitive pages.
2026-03-23T15:19:49Z
102 INFO SQLI No obvious SQLi on primary URL
Manual testing with specific parameters recommended.
2026-03-23T15:20:05Z
103 INFO CMS CMS detected: unknown 2026-03-23T15:21:12Z
104 INFO SSRF No in-band SSRF detected on common parameters
Out-of-band (OOB) SSRF may still exist. Use Burp Collaborator or Interactsh for blind testing.
2026-03-23T15:26:05Z