From 21f1685e5cd8a91cecc22751ad9c32b0a427cbf3 Mon Sep 17 00:00:00 2001 From: davidalvarezp Date: Mon, 23 Mar 2026 16:50:54 +0100 Subject: [PATCH] v1.0.1 --- demo/report/example.html | 896 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 896 insertions(+) create mode 100644 demo/report/example.html diff --git a/demo/report/example.html b/demo/report/example.html new file mode 100644 index 0000000..d8c97fd --- /dev/null +++ b/demo/report/example.html @@ -0,0 +1,896 @@ + + + + + +WebSec-Audit β€” example.com + + + +
+
+

WebSec-Audit β€” Security Report

+
https://example.com  |  2026-03-23 16:15:31  |  v1.0.1 by davidalvarezp
+
+
CRITICAL RISK
+
+
+ +
+
4
Critical
+
2
High
+
25
Medium
+
66
Low
+
7
Info
+
+ +
+
+
+
+
+
+ +
+
+

Scan Metadata

+
+ Target https://example.com + Domain example.com + IP 104.18.27.120 + Date 2026-03-23 16:15:31 + Duration 1541s + Auditor root@debian12 + Mode NORMAL +
+
+
+

Module Status

+
+ Recon βœ” enabled + Port Scan βœ” enabled + SSL/TLS βœ” enabled + Headers βœ” enabled + Dir Brute βœ” enabled + SQLi / XSS βœ” / βœ” + CMS βœ” enabled + Nuclei βœ” enabled +
+
+
+ +

Security Findings (104)

+
+ + + + + + + +
+ +
No findings match the current filter.
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
#SeverityModuleFindingTimestamp
1INFOINITAudit started against https://example.com
Resolved IP: 104.18.27.120 | Mode: NORMAL
2026-03-23T15:15:36Z
2INFORECONWHOIS data collected for example.com
Registrar: N/A | Expiry: 2026-08-13
2026-03-23T15:15:36Z
3INFORECONSubdomain enumeration: 37616 hosts discovered
0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com
/root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt
2026-03-23T15:16:22Z
4INFOFINGERPRINTWAF detected: Cloudflare (Cloudflare Inc.) WAF.
The target appears to be protected by a Web Application Firewall.
Cloudflare (Cloudflare Inc.) WAF.
2026-03-23T15:16:25Z
5LOWFINGERPRINTVersion disclosure via 'Server' header
The server reveals technology/version info in response headers.
Remove or neutralise the 'Server' header in your web server configuration.
2026-03-23T15:16:25Z
6LOWSSLtestssl: [TLS1] offered (deprecated)
Refer to testssl documentation for TLS1
2026-03-23T15:19:44Z
7LOWSSLtestssl: [TLS1_1] offered (deprecated)
Refer to testssl documentation for TLS1_1
2026-03-23T15:19:44Z
8MEDIUMSSLtestssl: [cipherlist_3DES_IDEA] offered
Refer to testssl documentation for cipherlist_3DES_IDEA
2026-03-23T15:19:44Z
9LOWSSLtestssl: [cipherlist_OBSOLETED] offered
Refer to testssl documentation for cipherlist_OBSOLETED
2026-03-23T15:19:44Z
10LOWSSLtestssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc013
2026-03-23T15:19:44Z
11LOWSSLtestssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_x2f
2026-03-23T15:19:44Z
12LOWSSLtestssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc014
2026-03-23T15:19:44Z
13LOWSSLtestssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_x35
2026-03-23T15:19:44Z
14MEDIUMSSLtestssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA
Refer to testssl documentation for cipher-tls1_x0a
2026-03-23T15:19:44Z
15LOWSSLtestssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc013
2026-03-23T15:19:44Z
16LOWSSLtestssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x2f
2026-03-23T15:19:44Z
17LOWSSLtestssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc014
2026-03-23T15:19:44Z
18LOWSSLtestssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x35
2026-03-23T15:19:44Z
19LOWSSLtestssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc009
2026-03-23T15:19:44Z
20LOWSSLtestssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc00a
2026-03-23T15:19:44Z
21LOWSSLtestssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc023
2026-03-23T15:19:44Z
22LOWSSLtestssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc024
2026-03-23T15:19:44Z
23LOWSSLtestssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc013
2026-03-23T15:19:45Z
24LOWSSLtestssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x2f
2026-03-23T15:19:45Z
25LOWSSLtestssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc014
2026-03-23T15:19:45Z
26LOWSSLtestssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x35
2026-03-23T15:19:45Z
27LOWSSLtestssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25
Refer to testssl documentation for cipher-tls1_2_xc027
2026-03-23T15:19:45Z
28LOWSSLtestssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3c
2026-03-23T15:19:45Z
29LOWSSLtestssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38
Refer to testssl documentation for cipher-tls1_2_xc028
2026-03-23T15:19:45Z
30LOWSSLtestssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3d
2026-03-23T15:19:45Z
31HIGHSSLtestssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'
Refer to testssl documentation for cert_keyUsage <hostCert#1>
2026-03-23T15:19:45Z
32CRITICALSSLtestssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#1>
2026-03-23T15:19:45Z
33MEDIUMSSLtestssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#1>
2026-03-23T15:19:45Z
34MEDIUMSSLtestssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#1>
2026-03-23T15:19:45Z
35LOWSSLtestssl: [DNS_CAArecord <hostCert#1>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#1>
2026-03-23T15:19:45Z
36CRITICALSSLtestssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#2>
2026-03-23T15:19:45Z
37MEDIUMSSLtestssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#2>
2026-03-23T15:19:45Z
38MEDIUMSSLtestssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#2>
2026-03-23T15:19:45Z
39LOWSSLtestssl: [DNS_CAArecord <hostCert#2>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#2>
2026-03-23T15:19:45Z
40LOWSSLtestssl: [HSTS] not offered
Refer to testssl documentation for HSTS
2026-03-23T15:19:46Z
41MEDIUMSSLtestssl: [security_headers] --
Refer to testssl documentation for security_headers
2026-03-23T15:19:46Z
42MEDIUMSSLtestssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested
Refer to testssl documentation for BREACH
2026-03-23T15:19:46Z
43LOWSSLtestssl: [SWEET32] uses 64 bit block ciphers
Refer to testssl documentation for SWEET32
2026-03-23T15:19:46Z
44MEDIUMSSLtestssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA
Refer to testssl documentation for BEAST_CBC_TLS1
2026-03-23T15:19:46Z
45LOWSSLtestssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
Refer to testssl documentation for BEAST
2026-03-23T15:19:46Z
46LOWSSLtestssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers
Refer to testssl documentation for LUCKY13
2026-03-23T15:19:46Z
47MEDIUMSSLtestssl: [overall_grade] B
Refer to testssl documentation for overall_grade
2026-03-23T15:19:46Z
48LOWSSLtestssl: [TLS1] offered (deprecated)
Refer to testssl documentation for TLS1
2026-03-23T15:19:46Z
49LOWSSLtestssl: [TLS1_1] offered (deprecated)
Refer to testssl documentation for TLS1_1
2026-03-23T15:19:46Z
50MEDIUMSSLtestssl: [cipherlist_3DES_IDEA] offered
Refer to testssl documentation for cipherlist_3DES_IDEA
2026-03-23T15:19:46Z
51LOWSSLtestssl: [cipherlist_OBSOLETED] offered
Refer to testssl documentation for cipherlist_OBSOLETED
2026-03-23T15:19:46Z
52LOWSSLtestssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc013
2026-03-23T15:19:46Z
53LOWSSLtestssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_x2f
2026-03-23T15:19:46Z
54LOWSSLtestssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_xc014
2026-03-23T15:19:46Z
55LOWSSLtestssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_x35
2026-03-23T15:19:46Z
56MEDIUMSSLtestssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA
Refer to testssl documentation for cipher-tls1_x0a
2026-03-23T15:19:46Z
57LOWSSLtestssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc013
2026-03-23T15:19:47Z
58LOWSSLtestssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x2f
2026-03-23T15:19:47Z
59LOWSSLtestssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_xc014
2026-03-23T15:19:47Z
60LOWSSLtestssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_1_x35
2026-03-23T15:19:47Z
61LOWSSLtestssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc009
2026-03-23T15:19:47Z
62LOWSSLtestssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc00a
2026-03-23T15:19:47Z
63LOWSSLtestssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc023
2026-03-23T15:19:47Z
64LOWSSLtestssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc024
2026-03-23T15:19:47Z
65LOWSSLtestssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc013
2026-03-23T15:19:47Z
66LOWSSLtestssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x2f
2026-03-23T15:19:47Z
67LOWSSLtestssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_xc014
2026-03-23T15:19:47Z
68LOWSSLtestssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
Refer to testssl documentation for cipher-tls1_2_x35
2026-03-23T15:19:47Z
69LOWSSLtestssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25
Refer to testssl documentation for cipher-tls1_2_xc027
2026-03-23T15:19:47Z
70LOWSSLtestssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3c
2026-03-23T15:19:47Z
71LOWSSLtestssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38
Refer to testssl documentation for cipher-tls1_2_xc028
2026-03-23T15:19:47Z
72LOWSSLtestssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
Refer to testssl documentation for cipher-tls1_2_x3d
2026-03-23T15:19:47Z
73HIGHSSLtestssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'
Refer to testssl documentation for cert_keyUsage <hostCert#1>
2026-03-23T15:19:47Z
74CRITICALSSLtestssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#1>
2026-03-23T15:19:47Z
75MEDIUMSSLtestssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#1>
2026-03-23T15:19:47Z
76MEDIUMSSLtestssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#1>
2026-03-23T15:19:48Z
77LOWSSLtestssl: [DNS_CAArecord <hostCert#1>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#1>
2026-03-23T15:19:48Z
78CRITICALSSLtestssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple
Refer to testssl documentation for cert_chain_of_trust <hostCert#2>
2026-03-23T15:19:48Z
79MEDIUMSSLtestssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)
Refer to testssl documentation for cert_expirationStatus <hostCert#2>
2026-03-23T15:19:48Z
80MEDIUMSSLtestssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57
Refer to testssl documentation for cert_notAfter <hostCert#2>
2026-03-23T15:19:48Z
81LOWSSLtestssl: [DNS_CAArecord <hostCert#2>] --
Refer to testssl documentation for DNS_CAArecord <hostCert#2>
2026-03-23T15:19:48Z
82LOWSSLtestssl: [HSTS] not offered
Refer to testssl documentation for HSTS
2026-03-23T15:19:48Z
83MEDIUMSSLtestssl: [security_headers] --
Refer to testssl documentation for security_headers
2026-03-23T15:19:48Z
84MEDIUMSSLtestssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested
Refer to testssl documentation for BREACH
2026-03-23T15:19:48Z
85LOWSSLtestssl: [SWEET32] uses 64 bit block ciphers
Refer to testssl documentation for SWEET32
2026-03-23T15:19:48Z
86MEDIUMSSLtestssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA
Refer to testssl documentation for BEAST_CBC_TLS1
2026-03-23T15:19:48Z
87LOWSSLtestssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
Refer to testssl documentation for BEAST
2026-03-23T15:19:48Z
88LOWSSLtestssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers
Refer to testssl documentation for LUCKY13
2026-03-23T15:19:48Z
89MEDIUMSSLtestssl: [overall_grade] B
Refer to testssl documentation for overall_grade
2026-03-23T15:19:48Z
90MEDIUMSSLCertificate expires in 52 days
May 14 18:57:50 2026 GMT
Plan certificate renewal.
2026-03-23T15:19:48Z
91MEDIUMSSLHSTS header not configured
Strict-Transport-Security is absent β€” browsers may access the site over HTTP.
Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
2026-03-23T15:19:49Z
92LOWHEADERSPermissions-Policy missing
The response is missing the 'permissions-policy' security header.
Add: Permissions-Policy: geolocation=(), microphone=(), camera=()
2026-03-23T15:19:49Z
93LOWHEADERSCross-Origin-Resource-Policy (CORP) missing
The response is missing the 'cross-origin-resource-policy' security header.
Add: Cross-Origin-Resource-Policy: same-origin
2026-03-23T15:19:49Z
94LOWHEADERSCross-Origin-Opener-Policy (COOP) missing
The response is missing the 'cross-origin-opener-policy' security header.
Add: Cross-Origin-Opener-Policy: same-origin
2026-03-23T15:19:49Z
95LOWHEADERSX-Content-Type-Options missing β€” MIME sniffing risk
The response is missing the 'x-content-type-options' security header.
Add: X-Content-Type-Options: nosniff
2026-03-23T15:19:49Z
96MEDIUMHEADERSX-Frame-Options missing β€” clickjacking risk
The response is missing the 'x-frame-options' security header.
Add: X-Frame-Options: SAMEORIGIN
2026-03-23T15:19:49Z
97MEDIUMHEADERSContent-Security-Policy (CSP) missing
The response is missing the 'content-security-policy' security header.
Implement a strict CSP to mitigate XSS and data injection attacks.
2026-03-23T15:19:49Z
98LOWHEADERSReferrer-Policy missing
The response is missing the 'referrer-policy' security header.
Add: Referrer-Policy: strict-origin-when-cross-origin
2026-03-23T15:19:49Z
99LOWHEADERSInformative header exposed: Server
Server reveals technology details via 'Server' header.
server: clo
Remove or anonymise the 'Server' header in your server configuration.
2026-03-23T15:19:49Z
100MEDIUMHEADERSHTTP does not redirect to HTTPS (HTTP 200)
Requests over HTTP are not automatically upgraded to HTTPS.
http://example.com β†’ 200
Configure a permanent 301 redirect from HTTP to HTTPS.
2026-03-23T15:19:49Z
101LOWHEADERSCache-Control header missing
Without Cache-Control, sensitive pages may be cached by intermediaries.
Add: Cache-Control: no-store, no-cache on authenticated/sensitive pages.
2026-03-23T15:19:49Z
102INFOSQLINo obvious SQLi on primary URL
Manual testing with specific parameters recommended.
2026-03-23T15:20:05Z
103INFOCMSCMS detected: unknown2026-03-23T15:21:12Z
104INFOSSRFNo in-band SSRF detected on common parameters
Out-of-band (OOB) SSRF may still exist. Use Burp Collaborator or Interactsh for blind testing.
2026-03-23T15:26:05Z
+
+ + +