your-site.com
Esempio di report del piano Pro. La mappatura della conformità, l'AI Library Health e il Deep Scan sono inclusi dal piano Pro in su — scopri cosa include ogni piano.
Questo è un esempio reale per un sito immaginario. Il tuo report viene generato da una scansione dal vivo del tuo dominio — stesse sezioni, stesso livello di dettaglio.
Cosa è cambiato dall'ultima scansione
Risolti dall'ultima scansione
- Alta Cross Site Scripting (Reflected)
- Bassa X-Content-Type-Options missing
- Media TLS 1.0 is enabled
Sintesi esecutiva
Questo rapporto copre la valutazione di sicurezza di your-site.com. Ha ottenuto un punteggio di 84/100, voto B (Hardening Recommended). Gli elementi aperti sono miglioramenti di hardening a gravità più bassa piuttosto che vulnerabilità sfruttabili. Dall'ultima scansione il punteggio è salito di 24 punto/i.
Problemi per gravità
Seleziona una gravità per vedere i risultati corrispondenti.
Esposizione al rischio stimata
Esposizione stimata in base ai risultati aperti in questo rapporto: £4,800.00 - £14,500.00
| Gravità | Aperti | Esposizione stimata |
|---|---|---|
| Media | 3 | £4,500.00 - £13,500.00 |
| Bassa | 1 | £300.00 - £1,000.00 |
L'esposizione al rischio stimata è una cifra illustrativa — non una valutazione, un preventivo o una garanzia. Moltiplica il numero di rilevamenti aperti per ciascuna gravità per una fascia di costo per gravità basata su studi pubblicati sul costo delle violazioni nel settore, adattata a un contesto di piccola impresa. Il costo effettivo dipende dai tuoi dati, clienti e circostanze. I rilevamenti informativi sono esclusi.
Punteggi per categoria
9 categorie su 16 valutate in questa scansione.
Non valutato in questa scansione
Warden non è riuscito a valutare queste aree in questa scansione (controlli saltati, errore di uno scanner o solo segnali informativi rilevati). Questo non conta né a favore né contro il tuo voto.
- Esposizione degli endpointNot assessed in this scan
- Igiene cloud / hostingNot assessed in this scan
- Postura CDN / WAFNot assessed in this scan
- Impronta digitaleNot assessed in this scan
- Intelligence su violazioni / minacceNot assessed in this scan
- Segnali di sviluppo sicuroNot assessed in this scan
- Avanzamento della remediationNot assessed in this scan
Copertura OWASP Top 10 (2021)
Problemi aperti mappati sulle categorie di rischio per applicazioni web dell’OWASP Top 10 (2021).
- A01 · Broken Access Control0
- A02 · Cryptographic Failures1
- A03 · Injection0
- A04 · Insecure Design0
- A05 · Security Misconfiguration3
- A06 · Vulnerable & Outdated Components0
- A07 · Identification & Authentication Failures0
- A08 · Software & Data Integrity Failures0
- A09 · Security Logging & Monitoring Failures0
- A10 · Server-Side Request Forgery0
Mappatura di conformità
I rilievi vengono mappati su CWE, OWASP e CVSS, e aggregati rispetto ai controlli PCI DSS, ISO 27001 e SOC 2 — una prova che puoi consegnare direttamente a un revisore.
PCI DSS 4.0
- 2.2.13 risultati aperti
- 6.4.13 risultati aperti
- 4.2.11 risultato aperto
- 3.5.11 risultato aperto
ISO/IEC 27001 2022 (Annex A)
- A.8.93 risultati aperti
- A.8.241 risultato aperto
SOC 2 Trust Services Criteria
- CC6.14 risultati aperti
- CC7.13 risultati aperti
- CC6.71 risultato aperto
Cyber Essentials
- Secure configuration4 risultati aperti
OWASP ASVS 4.0.3
- V143 risultati aperti
- V61 risultato aperto
- V91 risultato aperto
Principali risultati per rischio aziendale
I problemi aperti con il maggiore impatto potenziale sul business, ordinati per gravità e ricorrenza.
- 1Il certificato TLS scade entro 14 giorniMediaP2
If the certificate lapses, every visitor sees a full-page browser security warning and the site is effectively offline until it is renewed.
Correzione: Renew the certificate and automate renewal (for example with certbot or your host's managed TLS) so it cannot lapse again.
Interessato: https://your-site.com
- 2Nessun header Content-Security-PolicyMediaP1
Without a CSP, a single injected script — from a compromised third-party tag or an XSS flaw — can run unchecked. A CSP is the control that contains the damage when something else goes wrong.
Correzione: Add a Content-Security-Policy header. Start in report-only mode to find breakages, then enforce a policy that names your script origins explicitly and avoids unsafe-inline.
- 3Nessun record SPF pubblicato per il dominioMediaP2
Someone can send email that appears to come from your domain, and most receiving servers have no policy telling them otherwise — a common route into invoice fraud and phishing aimed at your customers.
Correzione: Publish an SPF TXT record listing every authorised sending service, ending in a policy (~all while testing, -all once confirmed).
- 4Nessun header Strict-Transport-SecurityBassaP3
A returning visitor who types the bare domain or follows an old http:// link is exposed to a downgrade attack on an untrusted network before HTTPS ever kicks in.
Correzione: Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every HTTPS response once you have confirmed all subdomains are HTTPS-only.
Roadmap delle priorità
Risultati aperti raggruppati per priorità comprensibile al cliente (P1 = agisci subito, P4 = informativo).
P1 — Rischio di sicurezza immediato (1)
Add a Content-Security-Policy header. Start in report-only mode to find breakages, then enforce a policy that names your script origins explicitly and avoids unsafe-inline.
P2 — Rafforzamento importante (2)
Renew the certificate and automate renewal (for example with certbot or your host's managed TLS) so it cannot lapse again.
Publish an SPF TXT record listing every authorised sending service, ending in a policy (~all while testing, -all once confirmed).
P3 — Miglioramento delle buone pratiche (1)
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every HTTPS response once you have confirmed all subdomains are HTTPS-only.
Piano di remediation
Vittorie rapide
- Il certificato TLS scade entro 14 giorni
- Nessun header Content-Security-Policy
- Nessun record SPF pubblicato per il dominio
- Nessun header Strict-Transport-Security
Lungo termine
- Applica gli header di sicurezza HTTP a livello globale (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) sul server web o sull'edge.
- Implementa SPF, DKIM e DMARC per il dominio per prevenire lo spoofing delle email.
- Imposta scansioni ricorrenti con confronto dei retest in modo che le regressioni vengano rilevate e i progressi monitorati nel tempo.
Risultati (4 di 4)
Panoramica dei risultati
| Problema | Gravità | Priorità | Responsabile |
|---|---|---|---|
| Nessun header Strict-Transport-Security | Bassa | P3 | Developer / server admin |
| Il certificato TLS scade entro 14 giorni | Media | P2 | Server / hosting admin |
| Nessun header Content-Security-Policy | Media | P1 | Developer / server admin |
| Nessun record SPF pubblicato per il dominio | Media | P2 | DNS / email admin |
Opportunità di hardening
Miglioramenti di difesa in profondità — non vulnerabilità attive.
P3Responsabile: Developer / server adminConfirmedInfluisce sul punteggio
Disponibile nel tuo account — contrassegna i problemi come risolti, accetta un rischio o chiedi una correzione all'IA.
The site does not send a Strict-Transport-Security header, so browsers do not remember to use HTTPS-only on a visitor's next visit.
- Impatto sul business
- A returning visitor who types the bare domain or follows an old http:// link is exposed to a downgrade attack on an untrusted network before HTTPS ever kicks in.
- Rischio tecnico
- Without HSTS a network attacker can strip HTTPS on the first request of a session, intercepting traffic before any redirect to HTTPS occurs.
- Come risolvere
- Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every HTTPS response once you have confirmed all subdomains are HTTPS-only.
- Come verificare
- Fetch the site over HTTPS and confirm the Strict-Transport-Security header is present with max-age of at least 31536000.
P2Responsabile: Server / hosting adminConfirmedInfluisce sul punteggio
Disponibile nel tuo account — contrassegna i problemi come risolti, accetta un rischio o chiedi una correzione all'IA.
The certificate presented by the site expires within 14 days.
- Impatto sul business
- If the certificate lapses, every visitor sees a full-page browser security warning and the site is effectively offline until it is renewed.
- Rischio tecnico
- An expired leaf certificate fails validation in all major browsers and in most API clients.
- Come risolvere
- Renew the certificate and automate renewal (for example with certbot or your host's managed TLS) so it cannot lapse again.
- Come verificare
- Re-run the scan after renewal and confirm the certificate expiry is more than 14 days out.
Interessato: https://your-site.com
P1Responsabile: Developer / server adminConfirmedInfluisce sul punteggio
Disponibile nel tuo account — contrassegna i problemi come risolti, accetta un rischio o chiedi una correzione all'IA.
The site does not send a Content-Security-Policy header, so the browser has no instruction limiting where scripts may be loaded from.
- Impatto sul business
- Without a CSP, a single injected script — from a compromised third-party tag or an XSS flaw — can run unchecked. A CSP is the control that contains the damage when something else goes wrong.
- Rischio tecnico
- No restriction on script-src, so any injected or third-party script executes with full origin privileges.
- Come risolvere
- Add a Content-Security-Policy header. Start in report-only mode to find breakages, then enforce a policy that names your script origins explicitly and avoids unsafe-inline.
- Come verificare
- Request any page and confirm a Content-Security-Policy response header is present and does not contain unsafe-inline in script-src.
Correzione suggerita dall'IA
Add a Content-Security-Policy header, starting in report-only mode so you can find what breaks before you enforce it.
Modifica suggerita nginx
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self'" always;Passaggi
1. Deploy the policy as Content-Security-Policy-Report-Only first. 2. Watch the browser console (and any report-uri endpoint) for a week to catch legitimate script origins you have missed. 3. Add those origins to script-src explicitly — avoid 'unsafe-inline'. 4. Switch the header to Content-Security-Policy to enforce it.
Convalida
Reload the site and confirm the Content-Security-Policy header is present and that no console errors report blocked legitimate resources.
Suggerimento assistito da IA — verificare prima di applicarlo.
P2Responsabile: DNS / email adminConfirmedInfluisce sul punteggio
Disponibile nel tuo account — contrassegna i problemi come risolti, accetta un rischio o chiedi una correzione all'IA.
The domain has no SPF record, so mail receivers cannot verify which servers are authorised to send mail on its behalf.
- Impatto sul business
- Someone can send email that appears to come from your domain, and most receiving servers have no policy telling them otherwise — a common route into invoice fraud and phishing aimed at your customers.
- Rischio tecnico
- Without an SPF TXT record, receivers fall back to their own default handling of unauthenticated senders, which is inconsistent and frequently permissive.
- Come risolvere
- Publish an SPF TXT record listing every authorised sending service, ending in a policy (~all while testing, -all once confirmed).
- Come verificare
- Query the domain's TXT records and confirm an SPF record (v=spf1 ...) is present.
Avvisi noti, liste di blocco e componenti a fine vita
Avvisi di sicurezza noti (CVE / GHSA, inclusi quelli CISA noti per essere sfruttati), componenti a fine vita e qualsiasi presenza in liste di blocco di sicurezza o blocco tramite filtro DNS rilevato su your-site.com. Le voci classificate come Basse o superiori contribuiscono al punteggio complessivo; le voci informative sono mostrate a scopo informativo.
Salute delle librerie IA · a titolo informativo
Your stack is broadly current. One package is no longer maintained and should be replaced, and two are far enough behind that upgrading them now will be easier than upgrading them later.
- laravel/framework 11.9.2Sana
Actively maintained and close to the latest release.
No action needed.
- moment 2.29.4Deprecata
Moment.js is in maintenance mode and its maintainers recommend migrating away.
Replace with date-fns, Day.js or the native Intl APIs.
- request 2.88.2Abbandonata
Deprecated since 2020 and no longer receiving security fixes.
Replace with the native fetch API or undici.
- guzzlehttp/guzzle 7.4.1Obsoleta
Several minor versions behind; later releases include security fixes.
Upgrade to the latest 7.x release.
Solo a titolo informativo — non incide sul tuo voto. Basato sui dati in tempo reale dei registri Packagist/npm al momento dell'analisi.
Cosa abbiamo controllato
Api
Il modulo Api ha eseguito 3 verifiche: 3 superati. Ha ottenuto un punteggio di 100/100. Non sono stati riscontrati errori.
Authn
Il modulo Authn ha eseguito 3 verifiche: 3 superati. Ha ottenuto un punteggio di 100/100. Non sono stati riscontrati errori.
Authz
Il modulo Authz ha eseguito 2 verifiche: 2 superati. Ha ottenuto un punteggio di 100/100. Non sono stati riscontrati errori.
Exposure
Il modulo Exposure ha eseguito 4 verifiche: 4 superati. Ha ottenuto un punteggio di 100/100. Non sono stati riscontrati errori.
Headers
Il modulo Headers ha eseguito 8 verifiche: 6 superati, 2 falliti. Ha ottenuto un punteggio di 65/100. 2 verifiche non sono riuscite e richiedono attenzione.
Infrastructure
Il modulo Infrastructure ha eseguito 5 verifiche: 4 superati, 1 fallito. 1 verifica non è riuscita e richiede attenzione.
Tls
Il modulo Tls ha eseguito 7 verifiche: 6 superati, 1 fallito. Ha ottenuto un punteggio di 43/100. 1 verifica non è riuscita e richiede attenzione.
Web App
Il modulo Web App ha eseguito 5 verifiche: 4 superati, 1 informativo. Ha ottenuto un punteggio di 100/100. Non sono stati riscontrati errori.
Risultati dei test
32 superati · 4 falliti · 0 avvisi · 37 totali
api
| API CORS policy is restrictive | superato |
| Every documented endpoint requires authentication | superato |
| No endpoint returned another account's records | superato |
authn
| Login form submits over HTTPS | superato |
| Session cookie sets Secure, HttpOnly and SameSite | superato |
| Signed in successfully with the supplied test account | superato |
authz
| No administrator-only page was reachable as a standard user | superato |
| Signed-in pages are not reachable while signed out | superato |
exposure
| File di ambiente .env non esposto | superato |
| .git/config non esposto | superato |
| archivio di backup non esposto | superato |
| Nessun elenco di directory in / | superato |
headers
| Content-Security-Policy mancante | fallito |
| HSTS (Strict-Transport-Security) mancante | fallito |
| A un cookie manca il flag Secure | superato |
| I Cookies usano HttpOnly | superato |
| Permissions-Policy presente | superato |
| Referrer-Policy presente | superato |
| X-Content-Type-Options presente | superato |
| X-Frame-Options mancante | superato |
infrastructure
| Nessun record SPF | fallito |
| 1 A record trovato | superato |
| Record DKIM presente (selector: default) | superato |
| Record DMARC presente | superato |
| L'header Server rivela la versione | superato |
tls
| Il certificato TLS scade entro 14 giorni | fallito |
| Controlli della catena dei certificati e della robustezza TLS superati | superato |
| Il certificato copre your-site.com | superato |
| Nessun cipher TLS debole rilevato | superato |
| TLS 1.0 è disabilitato | superato |
| Certificato TLS non scaduto per your-site.com | superato |
| Certificato TLS presente per your-site.com | superato |
web_app
| ZAP active scan ran authenticated, with the AJAX spider enabled | informativo |
| 2 sorgenti di script ad/analytics di terze parti presenti nell'HTML servito | superato |
| La policy CORS è restrittiva o assente | superato |
| Nessuna sottorisorsa mista (http://) nella pagina HTTPS | superato |
| ZAP active scan found no further injection issues | superato |
Evidenze
No Content-Security-Policy header (headers.csp)
Response headers with no Content-Security-Policy
HTTP/1.1 200 OK strict-transport-security: max-age=2592000 x-content-type-options: nosniff
Affidabilità della scansione
Alta(100/100)
Profondità e copertura della scansione
Profondità: Deep Scan (test attivi autenticati)
Warden esegue test di sicurezza automatizzati black-box dall'esterno — non ha accesso al codice sorgente dell'applicazione. Intere classi di problemi non possono quindi essere rilevate in modo esaustivo, tra cui difetti di logica di business e di autorizzazione, molti percorsi di injection memorizzata/di secondo ordine e cieca, vulnerabilità raggiungibili solo dietro autenticazione o in uno stato applicativo specifico, e debolezze a livello di progettazione. L'assenza di rilevamenti non dimostra che un sito sia privo di vulnerabilità.
Un Deep Scan aggiunge sondaggi attivi (injection di payload) ma rimane automatizzato e black-box; non equivale a un penetration test manuale completo con accesso al codice sorgente e analisi umana. Per esigenze ad alta affidabilità, commissiona una revisione assistita dal codice sorgente o manuale.
Guida alla gravità
- Critical — A serious flaw that is likely being or could easily be exploited. Fix immediately.
- High — An important weakness that could lead to compromise. Fix as a priority.
- Medium — A weakness that increases risk and should be scheduled for remediation.
- Low — A minor issue or hardening opportunity with limited direct impact.
- Info — Informational only — context for review, not a vulnerability by itself.
