Sample report — demo.example.com
A full example of what a completed scan looks like. Nothing here was produced by scanning a real site.
Security Score
Automated assessment. It does not replace a professional penetration test.
Findings
18
Pages discovered
34
Requests analyzed
51
Checks completed
26
Duration
132s
Mode
Full Audit
Executive summary
https://demo.example.com scored 82/100 across 26 passive checks. 1 finding(s) are rated high or critical, 4 medium and 7 low. Findings below are configuration observations with evidence and confidence attached — review each one in context before changing production settings.
Scoring methodology
Every scan starts at 100. Each open finding deducts points by severity; low-confidence findings deduct half. The score never drops below 0.
| Severity | Weight | Open | Deducted |
|---|---|---|---|
| critical | -40 | 0 | -0 |
| high | -20 | 1 | -20 |
| medium | -8 | 4 | -32 |
| low | -2 | 7 | -14 |
| informational | -0 | 6 | -0 |
Security headers
No policy returned for the main document.
HTTPS is served but not enforced for future visits.
MIME-type sniffing is not explicitly prevented.
Value does not restrict framing.
ALLOWALL
Browser default applies.
Powerful features are not restricted.
Cookie analysis
Use SameSite=Lax unless a cross-site flow requires None.
Add Secure so the cookie is only sent over HTTPS.
Cookie values are never stored or displayed.
HTTPS / TLS
- HTTPS
- Enabled
- Certificate
- Valid (connection succeeded)
- HTTP redirect
- Yes
- HSTS
- Missing
Technology exposure
- Servernginx/1.18.0
- X-Powered-ByExpress
Findings (18)
- HighConfidence: highPassive· Security Misconfiguration
Strict-Transport-Security header missing
https://demo.example.com/
- MediumConfidence: highPassive· Security Misconfiguration
Content-Security-Policy not set
https://demo.example.com/
- MediumConfidence: mediumPassive· Identification and Authentication Failures
Session cookie without SameSite attribute
https://demo.example.com/
- MediumConfidence: highPassive· Security Misconfiguration
Permissions-Policy not configured
https://demo.example.com/
- MediumConfidence: highPassive· Security Misconfiguration
Server software version disclosed
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
X-Frame-Options not set
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
Referrer-Policy not set
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
X-Content-Type-Options not set
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
Cookie without HttpOnly attribute
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
Framework fingerprint exposed via X-Powered-By
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
Directory listing indicator on /assets/
https://demo.example.com/
- LowConfidence: mediumPassive· Security Misconfiguration
Mixed-content resource reference found
https://demo.example.com/
- InfoConfidence: highPassive· Informational
robots.txt is publicly readable
https://demo.example.com/
- InfoConfidence: highPassive· Informational
sitemap.xml discovered
https://demo.example.com/
- InfoConfidence: highPassive· Informational
HTTP redirects to HTTPS
https://demo.example.com/
- InfoConfidence: highPassive· Informational
Cache-Control not set on main document
https://demo.example.com/
- InfoConfidence: highPassive· Informational
Third-party analytics script detected
https://demo.example.com/
- InfoConfidence: highPassive· Informational
Cross-origin resource sharing not enabled
https://demo.example.com/
Pages discovered
- https://demo.example.com/
- https://demo.example.com/pricing
- https://demo.example.com/docs
- https://demo.example.com/blog
- https://demo.example.com/contact
Scan limitations
- This is fabricated demo data — no website was scanned to produce it.
- Passive checks only: no authentication testing, no payloads, no destructive requests.
- An automated scan cannot replace a professional penetration test.