| Target | clovitek.com |
|---|---|
| Standards referenced | OWASP Top 10, Mozilla Observatory header model, CVSS v3.1, CIS / NIST hardening guidance |
| Scope | Primary host, automated remote evaluation (no authenticated or internal access) |
| Methodology | Remote probes of TLS, HTTP security headers, public exposure, reputation and performance. Automated remote scanning can verify only externally observable signals; controls that require manual review are marked Not Tested rather than assumed to pass. |
| Prepared by | CloviScan — automated audit engine |
This is an automated security audit, not a penetration test or compliance certification. Findings reflect signals observable from outside the target at scan time. Absence of a finding is not proof of security.
Score 66/100 — the site is at risk. 1 critical/high findings should be addressed immediately.
Rankings derived from real scan findings · no LLM in this path · fix labels reflect provenance of each remediation source
Open this URL inside a disposable, isolated browser container — it is never opened on a real machine. Captures the real rendered page, redirect chain, HTTP status, and a screenshot.
🔍 Run Live DetonationThe URL is opened only inside an isolated container with no access to our network. Container is destroyed immediately after capture.
Run a fresh scan right now to see what has changed since this report was generated. Shows score delta, resolved findings, and any new findings side-by-side.
Re-scan uses the same checks as the original scan. Results are cached after the verify run.
Automated scanning surfaced 10 findings, including 1 of critical/high severity that should be addressed first.
Weighted 0–100 across: TLS certificate (25) · certificate validity (10) · HTTP security headers (30, weighted over HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) · public exposure probes (20) · reputation (20) · performance (15). Controls marked Not Tested are never counted as passing.
Controls marked Not Tested were not exercised by this automated remote scan and are shown for transparency — they are never counted as passing or failing.
TLS/Cert
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Valid TLS certificate | Pass | — | A02 Cryptographic Failures | via TLS probe — issuer Google Trust Services, expires 2026-09-12 |
| Certificate long-term validity | Pass | — | A02 Cryptographic Failures | via cert expiry check — 87 days remaining |
| Cipher suite & TLS version grade | Pass | — | A02 Cryptographic Failures | via handshake — TLSv1.3 / TLS_AES_256_GCM_SHA384 |
Headers
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Strict-Transport-Security | Fail | High | A05 Security Misconfiguration | via header probe |
| Content-Security-Policy | Fail | Medium | A05 Security Misconfiguration | via header probe |
| X-Content-Type-Options | Pass | — | A05 Security Misconfiguration | via header probe |
| X-Frame-Options | Fail | Medium | A05 Security Misconfiguration | via header probe |
| Referrer-Policy | Fail | Low | A01 Broken Access Control | via header probe |
| Permissions-Policy | Fail | Low | A05 Security Misconfiguration | via header probe |
| Cookie flags (HttpOnly / Secure / SameSite) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
| CORS policy (ACAO with credentials) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
Exposure
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Public file/path exposure | Fail | Medium | A05 Security Misconfiguration | via 8 exposure probes |
| Mixed-content (HTTP subresources on HTTPS) | Pass | — | A02 Cryptographic Failures | via homepage HTML parse — none found |
| Dependency CVE / outdated component scan | Pass | — | A06 Vulnerable & Outdated Components | via banner fingerprint — 0 component(s) identified |
Reputation
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Malware / reputation | Pass | — | A08 Software & Data Integrity Failures | via safe-browsing lookup |
| DNS blocklist (DNSBL) reputation | Pass | — | A08 Software & Data Integrity Failures | via DNSBL — clean on 3 lists |
| Sucuri blacklist check | Not Tested | — | A08 Software & Data Integrity Failures | Sucuri data not available |
| Malware signature scan (Sucuri) | Not Tested | — | A08 Software & Data Integrity Failures | Sucuri data not available |
DNS
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| DNS records present | Pass | — | Info | A:2 MX:1 SPF:yes |
| DMARC / DKIM email-auth grading | Pass | — | A07 Identification & Authentication Failures | SPF:yes DMARC:yes DKIM:hint |
Network
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Open-port surface (common ports) | Fail | Medium | A05 Security Misconfiguration | external-vantage TCP probe to 172.67.132.164 — 3/14 open |
| Framework (reference only) | Relevant findings |
|---|---|
| PCI-DSS (TLS in transit) | TLS present |
| GDPR (data-in-transit) | HSTS missing — downgrade risk |
| OWASP ASVS V9 (Communications) | 1 high-priority finding(s) |
| CIS hardening benchmarks | Header & exposure controls evaluated above |
This mapping is for reference only and is not a certification of compliance with any framework.
Registration, DNS posture, email-authentication and network-surface intelligence gathered via standard remote lookups (WHOIS, DNS, TCP connect probe). External-safe — no intrusive scanning.
| Registrar | Cloudflare, Inc. |
| Created | 2016-08-14T20:13:54Z (~9y 308d old) |
| Expires | 2026-08-14T20:13:54Z (58 days) |
| Last updated | 2025-07-15T04:02:35Z |
| A records | 104.21.13.85, 172.67.132.164 |
| MX records | mail.clovitek.com |
| NS records | woz.ns.cloudflare.com, kay.ns.cloudflare.com |
| SPF | Yes v=spf1 ip4:158.220.120.58 a mx include:_spf.emailit.com ~all |
| DMARC | Yes v=DMARC1; p=none; rua=mailto:[email protected]; fo=1; adkim=r; aspf=r |
| DKIM (selector hint) | Yes |
| CAA | ssl.com, pki.goog; cansignhttpexchanges=yes, globalsign.com, letsencrypt.org |
DNSBL reputation: IP 172.67.132.164 — clean on 3 blocklists.
| Port | Service | Risk | Note |
|---|---|---|---|
| 80 | HTTP | INFO | Plain HTTP open (expected if it redirects to HTTPS). |
| 443 | HTTPS | INFO | HTTPS open (expected). |
| 8080 | HTTP-alt | MEDIUM | Port 8080 open to the internet — often exposes an admin panel or internal app server. Should not be publicly reachable. |
TLS handshake: TLSv1.3 · cipher TLS_AES_256_GCM_SHA384 · 256-bit key.
Fixing the top 3 issue(s) resolves the highest-severity exposure detected. Items are ordered Critical → Info.
Remote automated scanning cannot verify the following — they require authenticated or manual testing: