Sample report — demo.example.com

A full example of what a completed scan looks like. Nothing here was produced by scanning a real site.

DEMO DATA — this report was not produced by scanning a real website.
82/ 100

Security Score

Automated assessment. It does not replace a professional penetration test.

Findings

18

Pages discovered

34

Requests analyzed

51

Checks completed

26

Duration

132s

Mode

Full Audit

Executive summary

https://demo.example.com scored 82/100 across 26 passive checks. 1 finding(s) are rated high or critical, 4 medium and 7 low. Findings below are configuration observations with evidence and confidence attached — review each one in context before changing production settings.

Scoring methodology

Every scan starts at 100. Each open finding deducts points by severity; low-confidence findings deduct half. The score never drops below 0.

SeverityWeightOpenDeducted
critical-400-0
high-201-20
medium-84-32
low-27-14
informational-06-0

Security headers

Content-Security-PolicyMissing

No policy returned for the main document.

Strict-Transport-SecurityMissing

HTTPS is served but not enforced for future visits.

X-Content-Type-OptionsMissing

MIME-type sniffing is not explicitly prevented.

X-Frame-OptionsWeak

Value does not restrict framing.

ALLOWALL

Referrer-PolicyMissing

Browser default applies.

Permissions-PolicyMissing

Powerful features are not restricted.

Cookie analysis

sidMedium
Secure: yesHttpOnly: yesSameSite: None

Use SameSite=Lax unless a cross-site flow requires None.

prefsLow
Secure: noHttpOnly: noSameSite: Lax

Add Secure so the cookie is only sent over HTTPS.

Cookie values are never stored or displayed.

HTTPS / TLS

HTTPS
Enabled
Certificate
Valid (connection succeeded)
HTTP redirect
Yes
HSTS
Missing

Technology exposure

  • Servernginx/1.18.0
  • X-Powered-ByExpress

Findings (18)

  • HighConfidence: highPassive· Security Misconfiguration

    Strict-Transport-Security header missing

    https://demo.example.com/

  • MediumConfidence: highPassive· Security Misconfiguration

    Content-Security-Policy not set

    https://demo.example.com/

  • MediumConfidence: mediumPassive· Identification and Authentication Failures

    Session cookie without SameSite attribute

    https://demo.example.com/

  • MediumConfidence: highPassive· Security Misconfiguration

    Permissions-Policy not configured

    https://demo.example.com/

  • MediumConfidence: highPassive· Security Misconfiguration

    Server software version disclosed

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    X-Frame-Options not set

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    Referrer-Policy not set

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    X-Content-Type-Options not set

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    Cookie without HttpOnly attribute

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    Framework fingerprint exposed via X-Powered-By

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    Directory listing indicator on /assets/

    https://demo.example.com/

  • LowConfidence: mediumPassive· Security Misconfiguration

    Mixed-content resource reference found

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    robots.txt is publicly readable

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    sitemap.xml discovered

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    HTTP redirects to HTTPS

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    Cache-Control not set on main document

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    Third-party analytics script detected

    https://demo.example.com/

  • InfoConfidence: highPassive· Informational

    Cross-origin resource sharing not enabled

    https://demo.example.com/

Pages discovered

  • https://demo.example.com/
  • https://demo.example.com/pricing
  • https://demo.example.com/docs
  • https://demo.example.com/blog
  • https://demo.example.com/contact

Scan limitations

  • This is fabricated demo data — no website was scanned to produce it.
  • Passive checks only: no authentication testing, no payloads, no destructive requests.
  • An automated scan cannot replace a professional penetration test.