Top priorities
5 high-severity items
OWASP Top 10 (2021)
Passive-scan applicable categories
Technology stack
2 techs detected
Known vulnerabilities
Cross-referenced against retire.js and EOL data
Active vulnerability scan
Active scan engine unavailable
Web server audit
Web server audit engine unavailable
WordPress audit
Target is not a WordPress site, scan skipped
HTTP security headers
✓ present · ✗ missing
| Host | HSTS | CSP | X-Frame | Content-Type | Referrer | Perms | COOP |
|---|---|---|---|---|---|---|---|
| yourdomain.com.au | ✓ | ✗ | ✓ | ✓ | ✓ | ✗ | ✗ |
TLS & certificates
1 endpoint
- Issuer
- Google Trust Services
- Protocol
- TLSv1.3
- Expires
- 14 Sep 2026, 04:20 GMT
- Status
- Valid
TLS deep audit
1 endpoint probed · 8 findings
protocolsprotocolsprotocolsprotocolsvulnerabilitiesvulnerabilitiesvulnerabilitiesvulnerabilitiesEmail security
DMARC monitor-only (p=none)
Compliance snapshot
ISO 27001 · PCI-DSS · NIST CSF 2.0 · CIS Controls v8
DNS records
A · AAAA · MX · NS · TXT · SOA · CAA
A
172.66.40.147
172.66.43.109AAAA
2606:4700:3108::ac42:29f2
2606:4700:3109::ac42:2b6dMX
1 aspmx.l.google.com
5 alt1.aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 alt3.aspmx.l.google.com
10 alt4.aspmx.l.google.comNS
vin.ns.cloudflare.com
carolyn.ns.cloudflare.comSOA
vin.ns.cloudflare.com. dns.cloudflare.com. 2408149052 10000 2400 604800 1800CAA
No CAA record - without one, any CA can issue certificates for this domain.Subdomains (CT logs)
0 unique
Open ports
Port discovery unavailable
Subdomain takeover check
Fingerprinted against known vulnerable services
No subdomains discovered - apex and www checked directly, takeover check otherwise skipped.
OSINT & external exposure
Wayback Machine · search-engine dorks
Wayback Machine
97 snapshots- 1. http://yourdomain.com.au/
- 2. https://yourdomain.com.au/about
- 3. https://yourdomain.com.au/services
- 4. https://yourdomain.com.au/blog
- 5. https://yourdomain.com.au/contact
- 6. https://yourdomain.com.au/sitemap.xml
OSINT dork queries
All findings
Consolidated log across all checks · 97 total
| Sev | Category | Finding | Detail |
|---|---|---|---|
| Exposure | Exposed /config.php | HTTP 200 at yourdomain.com.au/config.php | |
| Exposure | Exposed /backup.sql | HTTP 200 at yourdomain.com.au/backup.sql | |
| Exposure | Exposed /backup.zip | HTTP 200 at yourdomain.com.au/backup.zip | |
| Exposure | Exposed /.aws/credentials | HTTP 200 at yourdomain.com.au/.aws/credentials | |
| Exposure | Exposed /server-status | HTTP 200 at yourdomain.com.au/server-status | |
| Exposure | Exposed /docker-compose.yml | HTTP 200 at yourdomain.com.au/docker-compose.yml | |
| Headers | Missing X-Frame-Options | Security header X-Frame-Options is absent | |
| DMARC policy is "none" | DMARC monitor-only, p=none | ||
| Exposure | Exposed /admin | HTTP 200 at yourdomain.com.au/admin | |
| DNS | No CAA record | Any CA can issue certs for this domain | |
| Headers | Missing Permissions-Policy | Security header Permissions-Policy is not set | |
| Headers | Missing COOP | Security header COOP is not set | |
| Recon | crt.sh lookup found | HTTPS/ConnectionPoolError (crt.sh, port:443) | |
| Active Scan | Port discovery skipped | Engine unavailable, not currently available for this scanner | |
| Web Server Scan | Web server audit skipped | Engine unavailable, not currently available for this scanner | |
| Active Vulnerability Scan | Active scan skipped | Engine unavailable, not currently available for this scanner |
Ready for the picture attackers can't see from outside?
Authenticated web & API testing, internal review, remediation-ready report aligned to your compliance frameworks.
Book a scoping call