Severities are the defaults. Vulnerability findings take their severity from CVSS and are raised
a step when the flaw is being exploited (see Vulnerability
matching). IDs with a part in angle brackets are patterns: the bracketed part is filled in per
finding, for example fingerprint.open-port-3389 or tls.cert-expiring@8443.
Findings are triaged per host and per ID: acknowledging, muting or accepting
headers.missing-csp on staging does not touch production. Mutes and risk acceptances
carry a review date (at most a year) and resurface on their own.
TLS and certificates · HTTP security headers · DNS and subdomains · Email security · Domain registration hygiene · Exposed services and fingerprinting · Known vulnerabilities · Web pages and privacy · Reputation
TLS and certificates
tls.cert-expired criticalCertificate is expired
What it means. Browsers and API clients refuse the connection. The site or service is effectively down for anyone who does not click through a warning.
How to fix. Renew and deploy a new certificate, then find out why automation did not: an expired certificate almost always means a renewal job failed silently.
tls.cert-expiring highCertificate expires soon
What it means. The served certificate is inside the warning window (30 days by default, adjustable per domain).
How to fix. Renew now, or confirm the automated renewal has a date before expiry and has run successfully recently.
tls.cert-expiring-soon lowCertificate expiry approaching
What it means. An early heads-up on a certificate approaching the warning window.
How to fix. No action needed if renewal is automated. If it is manual, schedule it.
tls.renewal-stalled mediumCertificate renewal looks stalled
What it means. A short-lived certificate is still being served past the point its automation would normally have replaced it (about 70% of its lifetime). This fires weeks before expiry does.
How to fix. Check the ACME client or certificate manager logs for that host and run a renewal by hand.
tls.untrusted-cert highCertificate did not validate
What it means. The chain does not lead to a publicly trusted root: self-signed, missing intermediate, or an internal CA.
How to fix. Serve the full chain (leaf plus intermediates) from a publicly trusted CA.
tls.hostname-mismatch highCertificate does not cover the hostname
What it means. The certificate's names (SANs) do not include the host being served, so clients reject it.
How to fix. Issue a certificate that lists this hostname, or route the hostname to the correct virtual host.
tls.weak-negotiated-protocol highWeak protocol negotiated
What it means. A default client handshake ended up on TLS 1.0 or 1.1, which every major browser has retired.
How to fix. Enable TLS 1.2 and 1.3 on the server or load balancer, and make them preferred.
tls.tls10-enabled mediumTLS 1.0 is accepted
What it means. The server still completes a TLS 1.0 handshake when asked. PCI DSS and most baselines require it off.
How to fix. Disable TLS 1.0 in the server, CDN or load balancer security policy.
tls.tls11-enabled mediumTLS 1.1 is accepted
What it means. As above, for TLS 1.1.
How to fix. Disable TLS 1.1 in the same policy.
tls.weak-key highWeak certificate key
What it means. The certificate's public key is below current minimums (for example RSA under 2048 bits).
How to fix. Reissue with an RSA 2048+ or ECDSA P-256+ key.
tls.weak-signature mediumCertificate signed with a weak algorithm
What it means. The leaf certificate is signed with SHA-1 or MD5, which are broken for signatures. Public CAs stopped issuing these years ago, so it is usually an old internal or appliance certificate.
How to fix. Reissue the certificate with a SHA-256 (or stronger) signature.
tls.<check>@<port> variesCertificate checks on extra ports
What it means. The certificate checks above, run on an extra port you added to the domain (for example a mail server or an admin console). The port is part of the ID so each endpoint triages separately.
How to fix. As for the matching check above.
tls.port-unreachable@<port> lowTLS on an extra port could not be checked
What it means. A port you asked us to watch did not complete a handshake.
How to fix. Remove the port from the domain's settings if it was retired, or check the service is up.
HTTP security headers
headers.no-https-redirect mediumHTTP does not redirect to HTTPS
What it means. Plain http:// serves content instead of redirecting, so a first visit can be intercepted or downgraded.
How to fix. Return a 301 from http:// to the https:// URL for every path.
headers.missing-hsts highMissing Strict-Transport-Security (HSTS)
What it means. Browsers are not told to insist on HTTPS, which leaves a window for downgrade and cookie theft on hostile networks.
How to fix. Send Strict-Transport-Security: max-age=31536000; includeSubDomains on HTTPS responses.
headers.weak-hsts lowHSTS max-age below 180 days
What it means. HSTS is present but expires quickly, so returning visitors lose the protection.
How to fix. Raise max-age to at least 15552000 (180 days); a year is common.
headers.missing-csp mediumMissing Content-Security-Policy
What it means. No policy limits where scripts and other resources may load from, so an injection bug has no second line of defence.
How to fix. Start with a report-only policy, tighten it, then enforce. Our free CSP builder at /tools/csp-builder helps.
headers.missing-nosniff lowMissing X-Content-Type-Options: nosniff
What it means. Browsers may guess content types, which can turn an upload into executable script.
How to fix. Send X-Content-Type-Options: nosniff on every response.
headers.clickjacking mediumNo clickjacking protection
What it means. Neither CSP frame-ancestors nor X-Frame-Options stops other sites framing the page.
How to fix. Send Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: DENY).
headers.missing-referrer-policy infoMissing Referrer-Policy
What it means. Full URLs, which can include tokens or identifiers, may leak to third parties in the Referer header.
How to fix. Send Referrer-Policy: strict-origin-when-cross-origin.
headers.server-version-disclosure lowServer version disclosed
What it means. The Server header names an exact version, which makes matching it against known vulnerabilities trivial for anyone.
How to fix. Configure the server to send a product name without a version, or no Server header.
headers.leak-<header> infoTechnology disclosed via a header
What it means. A header such as X-Powered-By names the framework behind the site.
How to fix. Remove the header at the application or proxy.
headers.cors-wildcard-credentials highCORS allows any origin with credentials
What it means. Any website can make authenticated requests to this host in a visitor's browser and read the answers.
How to fix. Reflect only an allowlist of trusted origins, and never combine a wildcard with Access-Control-Allow-Credentials.
headers.cors-wildcard infoCORS allows any origin
What it means. Access-Control-Allow-Origin: * without credentials. Fine for public APIs and assets, worth confirming elsewhere.
How to fix. Leave as is for public resources; restrict origins otherwise.
headers.cookie-flags-<name> mediumCookie missing security flags
What it means. A cookie is set without Secure, HttpOnly or SameSite. Medium when Secure is missing, low otherwise.
How to fix. Set Secure; HttpOnly; SameSite=Lax (or Strict) on session and authentication cookies.
headers.missing-security-txt infoNo security.txt
What it means. There is no /.well-known/security.txt telling researchers how to report a vulnerability to you. Checked on the apex only.
How to fix. Publish /.well-known/security.txt with at least Contact and Expires fields (RFC 9116; securitytxt.org has a generator).
headers.security-txt-expired lowsecurity.txt has expired
What it means. The file's Expires field has passed, is missing or cannot be parsed, so researchers are told not to trust the contact details. Apex only.
How to fix. Update the Expires field (keep it under a year out) and review the contacts.
DNS and subdomains
dns.dangling-cname-<host> highPossible subdomain takeover
What it means. A subdomain points (CNAME) at a hosted service, such as a storage bucket, Pages site or app platform, that no longer exists. Whoever claims that resource next serves content on your name.
How to fix. Delete the DNS record, or re-claim the resource on the provider before someone else does.
dns.missing-caa infoNo CAA record
What it means. Any public CA may issue certificates for the domain. CAA narrows that to the CAs you actually use.
How to fix. Publish CAA records naming your CAs (for example 0 issue "letsencrypt.org").
dns.attack-surface-inventory infoSubdomains observed in certificate transparency
What it means. An informational count of hostnames seen for the domain. The full list lives in the inventory.
How to fix. Nothing to fix. Review the inventory for hosts you do not recognise.
dns.dnssec-missing lowDNSSEC not enabled
What it means. The zone is not signed, so resolvers cannot detect forged answers. Checked on the apex only.
How to fix. Enable DNSSEC at your DNS provider, then publish the DS record at your registrar.
dns.dnssec-broken highDNSSEC validation fails
What it means. The parent zone has a DS record but the signatures do not validate, so validating resolvers (a large share of the internet) cannot resolve the domain at all.
How to fix. Re-sign the zone or remove the stale DS record at the registrar. This is usually the result of a DNS provider move.
Email security
dns.missing-spf mediumNo SPF record
What it means. Nothing says which servers may send mail as the domain, which makes spoofing easy and hurts deliverability.
How to fix. Publish a TXT record starting v=spf1 that lists your senders and ends in -all or ~all.
dns.soft-spf lowSPF uses soft-fail
What it means. The record ends in ~all, so receivers are asked to accept mail from unlisted servers, merely marked.
How to fix. Once DMARC reports show every legitimate sender is listed, switch to -all.
dns.missing-dmarc mediumNo DMARC record
What it means. Receivers have no policy for mail that fails SPF and DKIM, and you get no reports about who sends as you.
How to fix. Publish _dmarc TXT v=DMARC1; p=none; rua=mailto:... to start collecting reports, then move to quarantine or reject.
dns.dmarc-none lowDMARC policy is p=none
What it means. DMARC is in monitor mode: spoofed mail is reported but still delivered.
How to fix. Move to p=quarantine, then p=reject, once reports are clean.
dns.missing-mta-sts lowNo MTA-STS policy
What it means. Mail sent to you can be downgraded to plaintext by a network attacker. Only raised for domains that receive mail.
How to fix. Publish an _mta-sts TXT record and a policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt.
dns.mta-sts-policy-unreachable mediumMTA-STS policy file could not be fetched
What it means. The DNS record announces a policy but the policy file is missing or unreachable, so senders cannot apply it.
How to fix. Serve the policy file over HTTPS with a valid certificate for mta-sts.<domain>.
dns.mta-sts-testing lowMTA-STS policy is in testing mode
What it means. Failures are reported but mail is still delivered without TLS.
How to fix. Switch mode to enforce once TLS-RPT reports are clean.
dns.mta-sts-none lowMTA-STS policy mode is none
What it means. The policy exists but is switched off.
How to fix. Set mode: testing, then enforce.
dns.mta-sts-mx-mismatch mediumMTA-STS policy does not cover every MX host
What it means. An MX host is missing from the policy's mx lines, so enforcing senders will refuse to deliver to it. Medium in enforce mode, low otherwise.
How to fix. Add every MX host (or a matching wildcard) to the policy file and bump the policy id.
dns.missing-tlsrpt infoNo TLS-RPT record
What it means. You will not receive reports when senders fail to deliver to you over TLS.
How to fix. Publish _smtp._tls TXT v=TLSRPTv1; rua=mailto:...
Domain registration hygiene
dns.transfer-lock-missing mediumRegistrar transfer lock is off
What it means. The registration does not carry clientTransferProhibited, so a compromised registrar account or social-engineered support ticket can move the domain away.
How to fix. Turn on the transfer lock (often called Domain Lock) at your registrar. Some country-code registries do not support client locks; a registry-side (server) lock also counts as locked.
dns.update-lock-missing lowRegistrar update lock is off
What it means. clientUpdateProhibited is not set, so nameservers and contacts can be changed without an extra step.
How to fix. Enable the update lock, or ask the registrar about registry lock for high-value domains.
dns.delete-lock-missing lowRegistrar delete lock is off
What it means. clientDeleteProhibited is not set.
How to fix. Enable the delete lock at the registrar.
Exposed services and fingerprinting
fingerprint.open-port-<port> variesPort is reachable
What it means. A TCP connection to this port succeeded. Severity is set per port (123 in all): anything that should only be reached from a private network, such as databases, remote desktop, file shares, orchestration APIs and industrial protocols, is high; admin panels and brokers that are sometimes public on purpose are medium; normal public services are low or info. The full table is on Exposed services.
How to fix. Close the port at the firewall or security group, or restrict it to known source addresses or a VPN.
fingerprint.tech-disclosure infoTechnology stack fingerprinted
What it means. Informational record of the software and versions the host reveals. These product detections feed vulnerability matching.
How to fix. Nothing required. Reducing version disclosure makes the host a less obvious target.
Known vulnerabilities
vulns.cve-<cve id> variesKnown vulnerability in detected software
What it means. A product and version seen on the host is affected by this CVE (for example vulns.cve-2023-44487). Severity follows CVSS and is raised one step when the CVE is known to be exploited or likely to be. Tags carry CISA-KEV, EPSS:<score>, CWE-<n> and potential when the version could not be confirmed (potential matches are capped at medium).
How to fix. Upgrade to a fixed version, apply the vendor's mitigation, or accept the risk with a review date if a backport already covers it. See Vulnerability matching.
vulns.advisory-<ghsa id> variesKnown vulnerability in a front-end JavaScript library
What it means. A versioned JavaScript library referenced by the page (for example jQuery or Bootstrap) matches a published advisory that has no CVE number, identified by its GitHub advisory ID. Severity comes from the advisory.
How to fix. Upgrade the library to a fixed version and redeploy the page.
vulns.eol-<product> mediumSoftware past end of life
What it means. The detected version no longer receives security fixes from its vendor, so new vulnerabilities will not be patched.
How to fix. Plan an upgrade to a supported release line.
Web pages and privacy
web.login-form-http highLogin form without encryption
What it means. A page has a password field and either loads over plain HTTP or submits to an http:// address, so credentials cross the network in cleartext.
How to fix. Serve the page over HTTPS and make the form action an https:// URL.
web.pii-form-http highPersonal-data form without encryption
What it means. A form collecting personal data (email, phone, address, payment and similar fields) is served or submitted over HTTP.
How to fix. Serve and submit the form over HTTPS only.
web.form-posts-http highForm submits to an unencrypted address
What it means. A form on an HTTPS page posts to an http:// URL, so the data leaves the browser unencrypted.
How to fix. Change the form action to https://.
web.mixed-content variesMixed content
What it means. An HTTPS page loads resources over HTTP. Medium when active content (scripts, stylesheets, frames, objects) is involved, low when it is only images or media. Browsers block most active mixed content, and what they do not block can be tampered with.
How to fix. Load every sub-resource over HTTPS (or use protocol-relative paths you control).
web.third-party-script-no-sri lowThird-party script without integrity check
What it means. A script from another domain is loaded without a Subresource Integrity hash, so a compromise of that provider runs code on your page.
How to fix. Add integrity and crossorigin attributes for pinned versions, or self-host the script.
web.tracking-cookie-before-consent lowTracking cookie set before consent
What it means. A known analytics or advertising cookie arrives in the homepage's own Set-Cookie response, before any consent interaction is possible. The finding notes whether a consent manager was detected on the page. Relevant to GDPR and ePrivacy obligations.
How to fix. Gate the tag behind your consent manager so it only loads after opt-in.
Reputation
reputation.listed-<feed> highHost or IP on a blocklist
What it means. The hostname, or an IP address it resolves to, appears on a public abuse feed: reputation.listed-feodo, reputation.listed-urlhaus or reputation.listed-threatfox. Usually a compromised site or server. Downgraded to info when the only listed address is a shared CDN IP, where the listing is almost certainly about another customer.
How to fix. Investigate the host for compromise, clean it, then request delisting from the feed. See Reputation monitoring.