| Target | clovitek.com |
|---|---|
| Standards referenced | OWASP Top 10, Mozilla Observatory header model, CVSS v3.1, CIS / NIST hardening guidance |
| Scope | Primary host, automated remote evaluation (no authenticated or internal access) |
| Methodology | Remote probes of TLS, HTTP security headers, public exposure, reputation and performance. Automated remote scanning can verify only externally observable signals; controls that require manual review are marked Not Tested rather than assumed to pass. |
| Prepared by | CloviScan — automated audit engine |
This is an automated security audit, not a penetration test or compliance certification. Findings reflect signals observable from outside the target at scan time. Absence of a finding is not proof of security.
Automated scanning surfaced 4 findings.
Weighted 0–100 across: TLS certificate (25) · certificate validity (10) · HTTP security headers (30, weighted over HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) · public exposure probes (20) · reputation (20) · performance (15). Controls marked Not Tested are never counted as passing.
Controls marked Not Tested were not exercised by this automated remote scan and are shown for transparency — they are never counted as passing or failing.
TLS/Cert
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Valid TLS certificate | Pass | — | A02 Cryptographic Failures | via TLS probe — issuer Google Trust Services, expires 2026-09-12 |
| Certificate long-term validity | Pass | — | A02 Cryptographic Failures | via cert expiry check — 89 days remaining |
| Cipher suite & TLS version grade | Not Tested | — | A02 Cryptographic Failures | requires deeper / manual review |
Headers
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Strict-Transport-Security | Pass | — | A05 Security Misconfiguration | via header probe |
| Content-Security-Policy | Fail | Medium | A05 Security Misconfiguration | via header probe |
| X-Content-Type-Options | Pass | — | A05 Security Misconfiguration | via header probe |
| X-Frame-Options | Fail | Medium | A05 Security Misconfiguration | via header probe |
| Referrer-Policy | Fail | Low | A01 Broken Access Control | via header probe |
| Permissions-Policy | Fail | Low | A05 Security Misconfiguration | via header probe |
| Cookie flags (HttpOnly / Secure / SameSite) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
| CORS policy (ACAO with credentials) | Not Tested | — | A05 Security Misconfiguration | requires deeper / manual review |
Exposure
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Public file/path exposure | Pass | — | A05 Security Misconfiguration | via 9 exposure probes |
| Mixed-content (HTTP subresources on HTTPS) | Not Tested | — | A02 Cryptographic Failures | requires deeper / manual review |
| Dependency CVE / outdated component scan | Not Tested | — | A06 Vulnerable & Outdated Components | requires deeper / manual review |
Reputation
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| Malware / reputation | Pass | — | A08 Software & Data Integrity Failures | via safe-browsing lookup |
DNS
| Control | Status | Severity | OWASP | Source |
|---|---|---|---|---|
| DNS records present | Pass | — | Info | A:2 MX:1 SPF:yes |
| DMARC / DKIM email-auth grading | Not Tested | — | A07 Identification & Authentication Failures | requires deeper / manual review |
| Framework (reference only) | Relevant findings |
|---|---|
| PCI-DSS (TLS in transit) | TLS present |
| GDPR (data-in-transit) | Transport controls observed |
| OWASP ASVS V9 (Communications) | 0 high-priority finding(s) |
| CIS hardening benchmarks | Header & exposure controls evaluated above |
This mapping is for reference only and is not a certification of compliance with any framework.
Fixing the top 3 issue(s) resolves the highest-severity exposure detected. Items are ordered Critical → Info.
Remote automated scanning cannot verify the following — they require authenticated or manual testing: