| Target | clovitek.com |
|---|---|
| Standards referenced | OWASP Top 10, Mozilla Observatory header model, CVSS v3.1, CIS / NIST hardening guidance |
| Scope | Primary host, automated remote evaluation (no authenticated or internal access) |
| Methodology | Remote probes of TLS, HTTP security headers, public exposure, reputation and performance. Automated remote scanning can verify only externally observable signals; controls that require manual review are marked Not Tested rather than assumed to pass. |
| Prepared by | CloviScan — automated audit engine |
This is an automated security audit, not a penetration test or compliance certification. Findings reflect signals observable from outside the target at scan time. Absence of a finding is not proof of security.
Score 88/100 β hardening is needed. Security headers are the fastest wins; address them first.
Rankings derived from real scan findings Β· no LLM in this path Β· fix labels reflect provenance of each remediation source
Open this URL inside a disposable, isolated browser container β it is never opened on a real machine. Captures the real rendered page, redirect chain, HTTP status, and a screenshot.
π Run Live DetonationThe URL is opened only inside an isolated container with no access to our network. Container is destroyed immediately after capture.
Run a fresh scan right now to see what has changed since this report was generated. Shows score delta, resolved findings, and any new findings side-by-side.
Re-scan uses the same checks as the original scan. Results are cached after the verify run.
Automated scanning surfaced 4 findings, including 1 of critical/high severity that should be addressed first.
Weighted 0β100 across: TLS certificate (25) Β· certificate validity (10) Β· HTTP security headers (30, weighted over HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) Β· public exposure probes (20) Β· reputation (20) Β· performance (15). Controls marked Not Tested are never counted as passing.
Controls marked Not Tested were not exercised by this automated remote scan and are shown for transparency β they are never counted as passing or failing.
TLS/Cert
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Valid TLS certificate | Pass | β | A02 Cryptographic Failures | via TLS probe β issuer Google Trust Services, expires 2026-09-12 |
| Certificate long-term validity | Pass | β | A02 Cryptographic Failures | via cert expiry check β 42 days remaining |
| Cipher suite & TLS version grade | Pass | β | A02 Cryptographic Failures | via handshake β TLSv1.3 / TLS_AES_256_GCM_SHA384 |
Headers
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Strict-Transport-Security | Pass | β | A05 Security Misconfiguration | via header probe |
| Content-Security-Policy | Pass | β | A05 Security Misconfiguration | via header probe |
| X-Content-Type-Options | Pass | β | A05 Security Misconfiguration | via header probe |
| X-Frame-Options | Pass | β | A05 Security Misconfiguration | via header probe |
| Referrer-Policy | Pass | β | A01 Broken Access Control | via header probe |
| Permissions-Policy | Pass | β | A05 Security Misconfiguration | via header probe |
| Cookie flags (HttpOnly / Secure / SameSite) | Not Tested | β | A05 Security Misconfiguration | requires deeper / manual review |
| CORS policy (ACAO with credentials) | Not Tested | β | A05 Security Misconfiguration | requires deeper / manual review |
Exposure
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Public file/path exposure | Fail | Medium | A05 Security Misconfiguration | via 9 exposure probes |
| Mixed-content (HTTP subresources on HTTPS) | Pass | β | A02 Cryptographic Failures | via homepage HTML parse β none found |
| Dependency CVE / outdated component scan | Pass | β | A06 Vulnerable & Outdated Components | via banner fingerprint β 0 component(s) identified |
Reputation
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Malware / reputation | Pass | β | A08 Software & Data Integrity Failures | via safe-browsing lookup |
| DNS blocklist (DNSBL) reputation | Fail | High | A08 Software & Data Integrity Failures | via DNSBL β 1/3 listed |
| Sucuri blacklist check | Not Tested | β | A08 Software & Data Integrity Failures | Sucuri data not available |
| Malware signature scan (Sucuri) | Not Tested | β | A08 Software & Data Integrity Failures | Sucuri data not available |
DNS
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| DNS records present | Pass | β | Info | A:2 MX:1 SPF:yes |
| DMARC / DKIM email-auth grading | Pass | β | A07 Identification & Authentication Failures | SPF:yes DMARC:yes DKIM:hint |
Network
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Open-port surface (common ports) | Fail | Medium | A05 Security Misconfiguration | external-vantage TCP probe to 104.21.13.85 β 3/14 open |
| Framework (reference only) | Relevant findings |
|---|---|
| PCI-DSS (TLS in transit) | TLS present |
| GDPR (data-in-transit) | Transport controls observed |
| OWASP ASVS V9 (Communications) | 1 high-priority finding(s) |
| CIS hardening benchmarks | Header & exposure controls evaluated above |
This mapping is for reference only and is not a certification of compliance with any framework.
Registration, DNS posture, email-authentication and network-surface intelligence gathered via standard remote lookups (WHOIS, DNS, TCP connect probe). External-safe β no intrusive scanning.
| Registrar | Cloudflare, Inc. |
| Created | 2016-08-14T20:13:54Z (~9y 353d old) |
| Expires | 2027-08-14T20:13:54Z (378 days) |
| Last updated | 2026-07-15T04:03:44Z |
| A records | 104.21.13.85, 172.67.132.164 |
| MX records | mail.clovitek.com |
| NS records | kay.ns.cloudflare.com, woz.ns.cloudflare.com |
| SPF | Yes v=spf1 ip4:158.220.120.58 ip4:147.93.138.226 a mx include:_spf.emailit.com -all |
| DMARC | Yes v=DMARC1; p=none; rua=mailto:[email protected]; fo=1; adkim=r; aspf=r |
| DKIM (selector hint) | Yes |
| CAA | letsencrypt.org, digicert.com; cansignhttpexchanges=yes, globalsign.com, ssl.com |
DNSBL reputation: IP 104.21.13.85 β listed on 1/3 (zen.spamhaus.org).
| Port | Service | Risk | Note |
|---|---|---|---|
| 80 | HTTP | INFO | Plain HTTP open (expected if it redirects to HTTPS). |
| 443 | HTTPS | INFO | HTTPS open (expected). |
| 8080 | HTTP-alt | MEDIUM | Port 8080 open to the internet β often exposes an admin panel or internal app server. Should not be publicly reachable. |
TLS handshake: TLSv1.3 Β· cipher TLS_AES_256_GCM_SHA384 Β· 256-bit key.
Fixing the top 3 issue(s) resolves the highest-severity exposure detected. Items are ordered Critical β Info.
Remote automated scanning cannot verify the following β they require authenticated or manual testing: