| Target | testphp.vulnweb.com |
|---|---|
| Standards referenced | OWASP Top 10, Mozilla Observatory header model, CVSS v3.1, CIS / NIST hardening guidance |
| Scope | Primary host, automated remote evaluation (no authenticated or internal access) |
| Methodology | Remote probes of TLS, HTTP security headers, public exposure, reputation and performance. Automated remote scanning can verify only externally observable signals; controls that require manual review are marked Not Tested rather than assumed to pass. |
| Prepared by | CloviScan — automated audit engine |
This is an automated security audit, not a penetration test or compliance certification. Findings reflect signals observable from outside the target at scan time. Absence of a finding is not proof of security.
Score 40/100 — the site is at risk. 2 critical/high findings should be addressed immediately.
Rankings derived from real scan findings · no LLM in this path · fix labels reflect provenance of each remediation source
Automated scanning surfaced 7 findings, including 2 of critical/high severity that should be addressed first.
Weighted 0–100 across: TLS certificate (25) · certificate validity (10) · HTTP security headers (30, weighted over HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) · public exposure probes (20) · reputation (20) · performance (15). Controls marked Not Tested are never counted as passing.
Controls marked Not Tested were not exercised by this automated remote scan and are shown for transparency — they are never counted as passing or failing.
TLS/Cert
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Valid TLS certificate | Fail | Critical | A02 Cryptographic Failures | via TLS probe |
| Certificate long-term validity | Fail | High | A02 Cryptographic Failures | via cert expiry check |
| Cipher suite & TLS version grade | Not Tested | — | A02 Cryptographic Failures | TLS handshake detail unavailable |
Headers
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Strict-Transport-Security | Fail | High | A05 Security Misconfiguration | via header probe |
| Content-Security-Policy | Fail | Medium | A05 Security Misconfiguration | via header probe |
| X-Content-Type-Options | Fail | Low | A05 Security Misconfiguration | via header probe |
| X-Frame-Options | Fail | Medium | A05 Security Misconfiguration | via header probe |
| Referrer-Policy | Fail | Low | A01 Broken Access Control | via header probe |
| Permissions-Policy | Fail | Low | A05 Security Misconfiguration | via header probe |
| Cookie flags (HttpOnly / Secure / SameSite) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
| CORS policy (ACAO with credentials) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
Exposure
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Public file/path exposure | Pass | — | A05 Security Misconfiguration | via 9 exposure probes |
| Mixed-content (HTTP subresources on HTTPS) | Not Tested | — | A02 Cryptographic Failures | site not served over HTTPS / no HTML |
| Dependency CVE / outdated component scan | Not Tested | — | A06 Vulnerable & Outdated Components | no version banners observed |
Reputation
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Malware / reputation | Pass | — | A08 Software & Data Integrity Failures | via safe-browsing lookup |
| DNS blocklist (DNSBL) reputation | Not Tested | — | A08 Software & Data Integrity Failures | unavailable |
DNS
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| DNS records present | Pass | — | Info | A:1 MX:0 SPF:no |
| DMARC / DKIM email-auth grading | Not Tested | — | A07 Identification & Authentication Failures | email-auth DNS lookup unavailable |
Network
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Open-port surface (common ports) | Not Tested | — | A05 Security Misconfiguration | port probe unavailable |
| Framework (reference only) | Relevant findings |
|---|---|
| PCI-DSS (TLS in transit) | TLS issue detected |
| GDPR (data-in-transit) | HSTS missing — downgrade risk |
| OWASP ASVS V9 (Communications) | 2 high-priority finding(s) |
| CIS hardening benchmarks | Header & exposure controls evaluated above |
This mapping is for reference only and is not a certification of compliance with any framework.
Fixing the top 3 issue(s) resolves the highest-severity exposure detected. Items are ordered Critical → Info.
Remote automated scanning cannot verify the following — they require authenticated or manual testing: