Severities are the defaults. Vulnerability findings take their severity from CVSS and are raised a step when the flaw is being exploited (see Vulnerability matching). IDs with a part in angle brackets are patterns: the bracketed part is filled in per finding, for example fingerprint.open-port-3389 or tls.cert-expiring@8443.

Findings are triaged per host and per ID: acknowledging, muting or accepting headers.missing-csp on staging does not touch production. Mutes and risk acceptances carry a review date (at most a year) and resurface on their own.

TLS and certificates · HTTP security headers · DNS and subdomains · Email security · Domain registration hygiene · Exposed services and fingerprinting · Known vulnerabilities · Web pages and privacy · Reputation

TLS and certificates

tls.cert-expired critical

Certificate is expired

What it means. Browsers and API clients refuse the connection. The site or service is effectively down for anyone who does not click through a warning.

How to fix. Renew and deploy a new certificate, then find out why automation did not: an expired certificate almost always means a renewal job failed silently.

tls.cert-expiring high

Certificate expires soon

What it means. The served certificate is inside the warning window (30 days by default, adjustable per domain).

How to fix. Renew now, or confirm the automated renewal has a date before expiry and has run successfully recently.

tls.cert-expiring-soon low

Certificate expiry approaching

What it means. An early heads-up on a certificate approaching the warning window.

How to fix. No action needed if renewal is automated. If it is manual, schedule it.

tls.renewal-stalled medium

Certificate renewal looks stalled

What it means. A short-lived certificate is still being served past the point its automation would normally have replaced it (about 70% of its lifetime). This fires weeks before expiry does.

How to fix. Check the ACME client or certificate manager logs for that host and run a renewal by hand.

tls.untrusted-cert high

Certificate did not validate

What it means. The chain does not lead to a publicly trusted root: self-signed, missing intermediate, or an internal CA.

How to fix. Serve the full chain (leaf plus intermediates) from a publicly trusted CA.

tls.hostname-mismatch high

Certificate does not cover the hostname

What it means. The certificate's names (SANs) do not include the host being served, so clients reject it.

How to fix. Issue a certificate that lists this hostname, or route the hostname to the correct virtual host.

tls.weak-negotiated-protocol high

Weak protocol negotiated

What it means. A default client handshake ended up on TLS 1.0 or 1.1, which every major browser has retired.

How to fix. Enable TLS 1.2 and 1.3 on the server or load balancer, and make them preferred.

tls.tls10-enabled medium

TLS 1.0 is accepted

What it means. The server still completes a TLS 1.0 handshake when asked. PCI DSS and most baselines require it off.

How to fix. Disable TLS 1.0 in the server, CDN or load balancer security policy.

tls.tls11-enabled medium

TLS 1.1 is accepted

What it means. As above, for TLS 1.1.

How to fix. Disable TLS 1.1 in the same policy.

tls.weak-key high

Weak certificate key

What it means. The certificate's public key is below current minimums (for example RSA under 2048 bits).

How to fix. Reissue with an RSA 2048+ or ECDSA P-256+ key.

tls.weak-signature medium

Certificate signed with a weak algorithm

What it means. The leaf certificate is signed with SHA-1 or MD5, which are broken for signatures. Public CAs stopped issuing these years ago, so it is usually an old internal or appliance certificate.

How to fix. Reissue the certificate with a SHA-256 (or stronger) signature.

tls.<check>@<port> varies

Certificate checks on extra ports

What it means. The certificate checks above, run on an extra port you added to the domain (for example a mail server or an admin console). The port is part of the ID so each endpoint triages separately.

How to fix. As for the matching check above.

tls.port-unreachable@<port> low

TLS on an extra port could not be checked

What it means. A port you asked us to watch did not complete a handshake.

How to fix. Remove the port from the domain's settings if it was retired, or check the service is up.

HTTP security headers

headers.no-https-redirect medium

HTTP does not redirect to HTTPS

What it means. Plain http:// serves content instead of redirecting, so a first visit can be intercepted or downgraded.

How to fix. Return a 301 from http:// to the https:// URL for every path.

headers.missing-hsts high

Missing Strict-Transport-Security (HSTS)

What it means. Browsers are not told to insist on HTTPS, which leaves a window for downgrade and cookie theft on hostile networks.

How to fix. Send Strict-Transport-Security: max-age=31536000; includeSubDomains on HTTPS responses.

headers.weak-hsts low

HSTS max-age below 180 days

What it means. HSTS is present but expires quickly, so returning visitors lose the protection.

How to fix. Raise max-age to at least 15552000 (180 days); a year is common.

headers.missing-csp medium

Missing Content-Security-Policy

What it means. No policy limits where scripts and other resources may load from, so an injection bug has no second line of defence.

How to fix. Start with a report-only policy, tighten it, then enforce. Our free CSP builder at /tools/csp-builder helps.

headers.missing-nosniff low

Missing X-Content-Type-Options: nosniff

What it means. Browsers may guess content types, which can turn an upload into executable script.

How to fix. Send X-Content-Type-Options: nosniff on every response.

headers.clickjacking medium

No clickjacking protection

What it means. Neither CSP frame-ancestors nor X-Frame-Options stops other sites framing the page.

How to fix. Send Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: DENY).

headers.missing-referrer-policy info

Missing Referrer-Policy

What it means. Full URLs, which can include tokens or identifiers, may leak to third parties in the Referer header.

How to fix. Send Referrer-Policy: strict-origin-when-cross-origin.

headers.server-version-disclosure low

Server version disclosed

What it means. The Server header names an exact version, which makes matching it against known vulnerabilities trivial for anyone.

How to fix. Configure the server to send a product name without a version, or no Server header.

headers.leak-<header> info

Technology disclosed via a header

What it means. A header such as X-Powered-By names the framework behind the site.

How to fix. Remove the header at the application or proxy.

headers.cors-wildcard-credentials high

CORS allows any origin with credentials

What it means. Any website can make authenticated requests to this host in a visitor's browser and read the answers.

How to fix. Reflect only an allowlist of trusted origins, and never combine a wildcard with Access-Control-Allow-Credentials.

headers.cors-wildcard info

CORS allows any origin

What it means. Access-Control-Allow-Origin: * without credentials. Fine for public APIs and assets, worth confirming elsewhere.

How to fix. Leave as is for public resources; restrict origins otherwise.

headers.missing-security-txt info

No security.txt

What it means. There is no /.well-known/security.txt telling researchers how to report a vulnerability to you. Checked on the apex only.

How to fix. Publish /.well-known/security.txt with at least Contact and Expires fields (RFC 9116; securitytxt.org has a generator).

headers.security-txt-expired low

security.txt has expired

What it means. The file's Expires field has passed, is missing or cannot be parsed, so researchers are told not to trust the contact details. Apex only.

How to fix. Update the Expires field (keep it under a year out) and review the contacts.

DNS and subdomains

dns.dangling-cname-<host> high

Possible subdomain takeover

What it means. A subdomain points (CNAME) at a hosted service, such as a storage bucket, Pages site or app platform, that no longer exists. Whoever claims that resource next serves content on your name.

How to fix. Delete the DNS record, or re-claim the resource on the provider before someone else does.

dns.missing-caa info

No CAA record

What it means. Any public CA may issue certificates for the domain. CAA narrows that to the CAs you actually use.

How to fix. Publish CAA records naming your CAs (for example 0 issue "letsencrypt.org").

dns.attack-surface-inventory info

Subdomains observed in certificate transparency

What it means. An informational count of hostnames seen for the domain. The full list lives in the inventory.

How to fix. Nothing to fix. Review the inventory for hosts you do not recognise.

dns.dnssec-missing low

DNSSEC not enabled

What it means. The zone is not signed, so resolvers cannot detect forged answers. Checked on the apex only.

How to fix. Enable DNSSEC at your DNS provider, then publish the DS record at your registrar.

dns.dnssec-broken high

DNSSEC validation fails

What it means. The parent zone has a DS record but the signatures do not validate, so validating resolvers (a large share of the internet) cannot resolve the domain at all.

How to fix. Re-sign the zone or remove the stale DS record at the registrar. This is usually the result of a DNS provider move.

Email security

dns.missing-spf medium

No SPF record

What it means. Nothing says which servers may send mail as the domain, which makes spoofing easy and hurts deliverability.

How to fix. Publish a TXT record starting v=spf1 that lists your senders and ends in -all or ~all.

dns.soft-spf low

SPF uses soft-fail

What it means. The record ends in ~all, so receivers are asked to accept mail from unlisted servers, merely marked.

How to fix. Once DMARC reports show every legitimate sender is listed, switch to -all.

dns.missing-dmarc medium

No DMARC record

What it means. Receivers have no policy for mail that fails SPF and DKIM, and you get no reports about who sends as you.

How to fix. Publish _dmarc TXT v=DMARC1; p=none; rua=mailto:... to start collecting reports, then move to quarantine or reject.

dns.dmarc-none low

DMARC policy is p=none

What it means. DMARC is in monitor mode: spoofed mail is reported but still delivered.

How to fix. Move to p=quarantine, then p=reject, once reports are clean.

dns.missing-mta-sts low

No MTA-STS policy

What it means. Mail sent to you can be downgraded to plaintext by a network attacker. Only raised for domains that receive mail.

How to fix. Publish an _mta-sts TXT record and a policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt.

dns.mta-sts-policy-unreachable medium

MTA-STS policy file could not be fetched

What it means. The DNS record announces a policy but the policy file is missing or unreachable, so senders cannot apply it.

How to fix. Serve the policy file over HTTPS with a valid certificate for mta-sts.<domain>.

dns.mta-sts-testing low

MTA-STS policy is in testing mode

What it means. Failures are reported but mail is still delivered without TLS.

How to fix. Switch mode to enforce once TLS-RPT reports are clean.

dns.mta-sts-none low

MTA-STS policy mode is none

What it means. The policy exists but is switched off.

How to fix. Set mode: testing, then enforce.

dns.mta-sts-mx-mismatch medium

MTA-STS policy does not cover every MX host

What it means. An MX host is missing from the policy's mx lines, so enforcing senders will refuse to deliver to it. Medium in enforce mode, low otherwise.

How to fix. Add every MX host (or a matching wildcard) to the policy file and bump the policy id.

dns.missing-tlsrpt info

No TLS-RPT record

What it means. You will not receive reports when senders fail to deliver to you over TLS.

How to fix. Publish _smtp._tls TXT v=TLSRPTv1; rua=mailto:...

Domain registration hygiene

dns.transfer-lock-missing medium

Registrar transfer lock is off

What it means. The registration does not carry clientTransferProhibited, so a compromised registrar account or social-engineered support ticket can move the domain away.

How to fix. Turn on the transfer lock (often called Domain Lock) at your registrar. Some country-code registries do not support client locks; a registry-side (server) lock also counts as locked.

dns.update-lock-missing low

Registrar update lock is off

What it means. clientUpdateProhibited is not set, so nameservers and contacts can be changed without an extra step.

How to fix. Enable the update lock, or ask the registrar about registry lock for high-value domains.

dns.delete-lock-missing low

Registrar delete lock is off

What it means. clientDeleteProhibited is not set.

How to fix. Enable the delete lock at the registrar.

Exposed services and fingerprinting

fingerprint.open-port-<port> varies

Port is reachable

What it means. A TCP connection to this port succeeded. Severity is set per port (123 in all): anything that should only be reached from a private network, such as databases, remote desktop, file shares, orchestration APIs and industrial protocols, is high; admin panels and brokers that are sometimes public on purpose are medium; normal public services are low or info. The full table is on Exposed services.

How to fix. Close the port at the firewall or security group, or restrict it to known source addresses or a VPN.

fingerprint.tech-disclosure info

Technology stack fingerprinted

What it means. Informational record of the software and versions the host reveals. These product detections feed vulnerability matching.

How to fix. Nothing required. Reducing version disclosure makes the host a less obvious target.

Known vulnerabilities

vulns.cve-<cve id> varies

Known vulnerability in detected software

What it means. A product and version seen on the host is affected by this CVE (for example vulns.cve-2023-44487). Severity follows CVSS and is raised one step when the CVE is known to be exploited or likely to be. Tags carry CISA-KEV, EPSS:<score>, CWE-<n> and potential when the version could not be confirmed (potential matches are capped at medium).

How to fix. Upgrade to a fixed version, apply the vendor's mitigation, or accept the risk with a review date if a backport already covers it. See Vulnerability matching.

vulns.advisory-<ghsa id> varies

Known vulnerability in a front-end JavaScript library

What it means. A versioned JavaScript library referenced by the page (for example jQuery or Bootstrap) matches a published advisory that has no CVE number, identified by its GitHub advisory ID. Severity comes from the advisory.

How to fix. Upgrade the library to a fixed version and redeploy the page.

vulns.eol-<product> medium

Software past end of life

What it means. The detected version no longer receives security fixes from its vendor, so new vulnerabilities will not be patched.

How to fix. Plan an upgrade to a supported release line.

Web pages and privacy

web.login-form-http high

Login form without encryption

What it means. A page has a password field and either loads over plain HTTP or submits to an http:// address, so credentials cross the network in cleartext.

How to fix. Serve the page over HTTPS and make the form action an https:// URL.

web.pii-form-http high

Personal-data form without encryption

What it means. A form collecting personal data (email, phone, address, payment and similar fields) is served or submitted over HTTP.

How to fix. Serve and submit the form over HTTPS only.

web.form-posts-http high

Form submits to an unencrypted address

What it means. A form on an HTTPS page posts to an http:// URL, so the data leaves the browser unencrypted.

How to fix. Change the form action to https://.

web.mixed-content varies

Mixed content

What it means. An HTTPS page loads resources over HTTP. Medium when active content (scripts, stylesheets, frames, objects) is involved, low when it is only images or media. Browsers block most active mixed content, and what they do not block can be tampered with.

How to fix. Load every sub-resource over HTTPS (or use protocol-relative paths you control).

web.third-party-script-no-sri low

Third-party script without integrity check

What it means. A script from another domain is loaded without a Subresource Integrity hash, so a compromise of that provider runs code on your page.

How to fix. Add integrity and crossorigin attributes for pinned versions, or self-host the script.

Reputation

reputation.listed-<feed> high

Host or IP on a blocklist

What it means. The hostname, or an IP address it resolves to, appears on a public abuse feed: reputation.listed-feodo, reputation.listed-urlhaus or reputation.listed-threatfox. Usually a compromised site or server. Downgraded to info when the only listed address is a shared CDN IP, where the listing is almost certainly about another customer.

How to fix. Investigate the host for compromise, clean it, then request delisting from the feed. See Reputation monitoring.