A complete Soryvex report, in full.
This is not a mock-up. It is a real assessment of
lab.soryvex.com — our own
website — run by the same engine that assesses a customer's site and rendered
through the same report you get. Every finding, score and severity below is the
engine's own output.
- Subject
- lab.soryvex.com
- Risk score
- 20.3 / 100 · LOW
- Confirmed findings
- 1
- Generated
- 2026-10-08
Regenerated weekly. It is a real run rather than a live one, so the score and findings above are as they stood on that date.
Security Assessment Report
lab.soryvex.com
Executive Summary
lab.soryvex.com received a 20.3/100 Low risk rating based exclusively on 1 confirmed security finding. No high or critical severity confirmed findings were identified.
What this score means
Low — No confirmed finding above low severity. Remaining items are hardening opportunities, not an active breach.
- What set it: The worst confirmed finding here is at this severity. These are hardening gaps: real and worth closing, but they do not on their own put the score in a dangerous band.
- How it is counted: only confirmed findings move this number. Likely findings add to it but cannot raise it into a band on their own, and observations and verified controls never move it at all. “Confirmed” means Soryvex observed the condition and attached the evidence below — it does not mean the condition was exploited, and this assessment did not attempt to exploit anything.
- Findings counted: 1 in total, from the confirmed and likely sections of this report.
- How much of the discovered surface was probed: high confidence — 459 active probe requests against 483 discovered parameters and endpoints. This is a measure of the active testing that was possible, not of the whole assessment.
The score is calculated the same way for every domain, so the same site assessed twice gives the same number. It is a measure of what was exposed from outside, not a measure of everything that could ever go wrong.
Fix these first
Ordered by severity, then by how many assets each one affects. Everything listed here is a finding in this report — the link takes you to it.
- LOW
Soryvex AI Analyst Review
AI Analyst unavailable for this assessment.
Confirmed Findings
| Severity | Finding | Confidence | Affected Asset |
|---|---|---|---|
| LOW |
Redirect scan unavailable
Affects 1 asset ·
RED-001
|
Low | https://lab.soryvex.com |
https://lab.soryvex.com
Likely Findings
No likely issues were identified during this assessment.
Findings Needing Review
No findings requiring manual review were identified during this assessment.
Potential Issues
Issues that may warrant investigation but could not be conclusively validated with the available evidence.
| Severity | Finding | Confidence | Affected Asset(s) | What was observed |
|---|---|---|---|---|
| MEDIUM |
DNSSEC not detected
Affects 1 asset ·
DNS-008
|
High | lab.soryvex.com |
DS record absent; DNSSEC validation unavailable. |
Security Observations
DNS & Email
DNS-007
CAA record not published — CAA not published; no CA restriction configured.
DNS-030
Common subdomains resolved — Resolved common subdomains: none
DNS-004
DMARC record not published — No _dmarc TXT record; consider publishing one to align mail authentication.
DNS-010
MTA-STS policy not configured — MTA-STS TXT absent; MTA-STS not enforced.
DNS-009
Nameservers missing — No NS records resolved.
EML-013
No BIMI record published — No default._bimi.<domain> TXT record was found. BIMI attaches a brand indicator to mail so receiving clients can show a verified logo; without it, brand impersonation in the inbox…
DNS-006
No MX records published — No MX records found; the domain does not publish an inbound-mail relay. This is not by itself a vulnerability — the domain may not intend to receive mail — but email-security harde…
DNS-005
No common DKIM selectors found — No DKIM TXT records found for common selectors; consider configuring DKIM signing.
DNS-025
No nameservers resolved — No authoritative nameservers were resolved.
DNS-002
SPF record not published — No SPF TXT record found; consider publishing one to define authorized mail senders.
DNS-011
TLS-RPT not configured — TLS reporting TXT absent.
Technology
INFRA-001
Cloudflare CDN detected — The target uses Cloudflare as a CDN or reverse proxy.
INFRA-002
Cloudflare WAF detected — The target appears to be protected by Cloudflare WAF.
Application Surface
AUT-001
Authentication scan unavailable — Base page unreachable (target has no public IP).
SYS-HTTP-FETCH
JavaScript scan unavailable — Base page unreachable (target has no public IP).
SYS-HTTP-FETCH
Source map scan unavailable — Base page unreachable (target has no public IP).
APP-005
robots.txt is published — Found /robots.txt (1248 bytes).
Verified Controls
DNS & Email
DNS-001Domain resolves correctlyDNS-012No CNAME at zone apexDNS-029No obvious DNS inconsistenciesDNS-015No wildcard DNSApplication Surface
SRI-001Cross-origin scripts protected by SRI (or none present)SRI-002Cross-origin stylesheets protected by SRI (or none present)VHOST-007Host-based routing behaved conventionallyFalse Positives
No false positives were identified during this assessment.
Not Verifiable & Limitations
CT-001No hostnames found in CT logs — certspotter responded but listed no certificates for this domain.SYS-MODULE-ERRHTTPS Delivery, HSTS & Certificate Scope: scan incomplete — The module could not complete its assessment because of an internal error. Results for this area are unknown (NOT VERIFIABLE).Application Surface Coverage
Coverage-only metrics from the discovery phase. These are inventory statistics and never contribute to the risk score.
| Check coverage | Checks |
|---|---|
| In Soryvex's check catalog | 568 |
| of which run without ownership verification | 245 |
| of which require verified ownership | 323 |
| Withheld from this run for want of ownership verification | 0 |
| Distinct checks that reported a finding in this run (a lower bound: a check that ran and found nothing is not counted) | 27 |
| Assessment target | Value |
|---|---|
| Submitted URL | https://lab.soryvex.com |
| Origin (DNS / TLS / infrastructure scope) | https://lab.soryvex.com |
| Application entry point crawled | https://lab.soryvex.com |
| Entry point requested | Yes |
| Entry point fetched | Yes (HTTP 200) |
| Entry point parsed as HTML | Yes |
| Application surface crawl | Completed |
| Metric | Discovered |
|---|---|
| Pages discovered | 1 |
| Pages fetched | 1 |
| Endpoints | 1 |
| Forms | 0 |
| Parameters | 0 |
| Scripts | 0 |
| API endpoints | 0 |
| WebSocket endpoints | 0 |
| Sitemap URLs | 0 |
| Robots paths | 0 |
| Requests used (discovery) | 1116 |
| Crawl limit reached | No |
Discovered vs. Actually Tested
1 endpoint was discovered during application-surface enumeration. This does not mean all of them were security-tested: each security module selects only relevant targets and operates within its configured safe probe limits, and several modules perform passive inspection instead of active probing. Discovery counts are inventory; the "tested / inspected" figures below are what the assessment actually exercised.
| Category | Discovered | Actually tested / inspected |
|---|---|---|
| Pages | 1 | — |
| Endpoints | 1 | 0 |
| Parameters (unique) | 0 | — |
| Parameter/endpoint pairs | per module | 0 |
| Forms | 0 | 0 |
| Scripts | 0 | 0 |
| API candidates | 0 | 0 |
| WebSocket endpoints | 0 | — |
| Active probe requests | — | 459 |
Fetch pipeline accounting
Where every discovered same-origin target went. A target is discovered once it is recorded in the application-surface inventory, queued when it is admitted to the bounded fetch queue, and fetched/parsed only when its response was a real HTML document. Anything that never reached the parse stage is listed under Rejected with the reason, so a low fetched count is always attributable to a specific cause (target unreachable, non-HTML response, configured cap, budget) rather than being a silent drop. Non-HTML responses are counted separately under Resources fetched and never consume the page budget.
| Stage | Count |
|---|---|
| Application surface crawl | Completed |
| Entry point fetched | Yes |
| Entry point parsed as HTML | Yes |
| Pages discovered (same-origin inventory) | 1 |
| Queued for fetch | 0 |
| Fetch requests issued | 0 |
| Pages fetched and parsed | 1 |
| Non-HTML resources fetched | 0 |
| Rejected (no usable document) | 0 |
| Skipped — off-origin | 0 |
| Skipped — duplicate path | 0 |
| Skipped — request budget exhausted | 0 |
| Configured crawl limit reached | No |
subdomains
no_subdomains_resolved — None of the 45 wordlist names resolved for lab.soryvex.com. Absence of results is not proof that no other subdomain exists; this is a passive wordlist only.
cloud_exposure
no_cloud_surface — No cloud storage, CDN or metadata reference was found in the HTML, scripts or configuration that were read.
file_exposure
no_sensitive_files — No stack-specific or stack-independent sensitive artifact was reachable. Technologies fingerprinted: cloudflare.
secrets
no_secrets_found — No credential-shaped value was found in the HTML, scripts, configuration endpoints or response headers that were read.
ops_exposure
no_ops_surface — None of the 60 operations, datastore and orchestration endpoints returned a response attributable to the product itself.
federation_surface
no_well_known_documents — None of the 30 conventional well-known paths responded with a document attributable to that product.
sitemap_surface
no_sitemap — None of the 10 conventional sitemap locations (nor any sitemap link on the home page or in robots.txt) returned a sitemap document.
content_discovery
no_new_paths — None of the 152 wordlist paths differed from this deployment's not-found response (HTTP 404), so no new endpoint was added to the surface.
virtual_hosts
no_additional_vhosts — None of the 20 names under lab.soryvex.com returned content distinct from the apex. This does not prove no other virtual host exists; it means none of the common names did.
cms_exposure
no_cms_detected — No content management system was fingerprinted from a response header or body, so no CMS-specific paths were probed.
dns_posture
no_mail_transport_policy — No MTA-STS or SMTP TLS-RPT record is published, so mail transport security is not enforced or reported.
cors_deep
no_cors_target — No HTML page was available to derive cross-origin request endpoints from; the deep CORS checks were skipped.
graphql
no_live_graphql — Candidate GraphQL paths did not behave like a GraphQL server.
http_attack_surface
no_root_response — The site root did not return a response; routing checks skipped.
websocket_surface
no_base_response — Neither the site root nor the assessed entry point could be fetched, so no realtime surface could be discovered.
prototype_pollution
no_probe_targets — No query parameter or GET-form input was discovered, so there is no observed request whose query string could be re-parsed into an object. Nothing was invented to probe.
form_security
no_pages — No page could be fetched, so no form markup was available to analyse.
third_party_surface
no_third_party_markup — This module fetched 2 page(s) and none referenced a script, stylesheet or iframe, so the third-party surface is empty by evidence rather than by assumption. This says nothing about routes outside the pages that were read.
authz
no_candidates — Application surface present but no discovered endpoint matches admin, ID-shaped, auth-parameter, POST form, or API criteria.
ssrf
no_url_fetch_params — Application surface present but no URL-fetch/webhook-shaped parameters were discovered; SSRF parameter observation skipped.
ssrf
no_fetch_urls — Application surface present but no fetch/proxy/import-style URL literals were found in JS fetch/XHR calls; server-side fetch observation skipped.
file_upload
no_upload_surface — Application surface present but no discovered form, API route or script reference indicates an upload surface; upload analysis skipped.
injection
no_probe_targets — Application surface present but no GET query parameters or GET-form inputs with names were discovered; parameter probing skipped.
xss
no_probe_targets — Application surface present but no GET query parameters or GET-form inputs with names were discovered; reflection probing skipped.
path_traversal
no_file_parameters — No observed parameter looks like a file/path input on a file-serving endpoint; path-traversal verification skipped.
command_injection
no_command_parameters — No observed parameter looks like a shell-input on a diagnostics/tool endpoint; command-injection verification skipped.
parameter_analysis
no_parameters — No query parameter or GET-form input was discovered, so parameter handling could not be analysed.
client_data_exposure
no_client_data_exposure — 1 script source(s) were analysed for client-side credential storage, personal data, internal routes, embedded operations and build-time configuration; none were present.
api_security
no_api_surface — Application surface present but no API endpoints or scripts were discovered by the crawler; API-security analysis used the fetched base page only.
Per-module coverage
One row per security module. "Parameter pairs" counts discovered endpoint+parameter pairs; "Resources inspected" counts passive inspection (scripts/forms); "Active probes" are requests sent against discovered targets. A zero in one column has a specific meaning shown by the module status — for example "Not applicable" (no relevant surface) or "Completed — passive inspection" — and never means the module was skipped. These numbers are coverage metadata and never affect the risk score.
| Module | Status | Endpoints | Parameter pairs | Resources inspected | Targets selected | Active probes | Skipped (limit) | Not relevant | Fallback |
|---|---|---|---|---|---|---|---|---|---|
api_security |
Not applicable | 0 | — | — | — | 0 | — | — | No |
attack_path |
Completed | — | — | — | — | 0 | — | — | No |
authz |
Not applicable | 0 | — | — | 0 | 0 | 0 | 0 | No |
client_data_exposure |
Completed | — | — | — | 0 | 0 | — | — | No |
cloud_exposure |
Completed | — | — | — | — | 0 | — | — | No |
cms_exposure |
Completed — partial coverage (6/25 tested, 24%) | — | — | — | 0 | 6 | — | — | No |
command_injection |
Not applicable | — | — | — | 0 | 0 | 0 | — | No |
content_discovery |
Completed | — | — | — | — | 153 | — | — | No |
cors_deep |
Completed | — | — | — | — | 0 | — | — | No |
dns_deep |
Completed | — | — | — | 1 | 1 | — | — | No |
dns_posture |
Completed | — | — | — | — | 8 | — | — | No |
federation_surface |
Completed | — | — | — | 0 | 30 | — | — | No |
file_exposure |
Completed | — | — | — | 0 | 76 | — | — | No |
file_upload |
Not applicable | — | — | 0 | — | 0 | — | — | No |
graphql |
Completed | — | — | — | — | 10 | — | — | No |
http_attack_surface |
Completed | — | — | — | — | 0 | — | — | No |
injection |
Completed | — | 0 | — | 0 | 0 | 0 | 0 | No |
javascript_deep |
Completed | — | — | — | — | 12 | — | — | No |
ops_exposure |
Completed | — | — | — | 0 | 60 | — | — | No |
parameter_analysis |
Completed | — | — | — | — | 0 | — | — | No |
path_traversal |
Not applicable | — | — | — | 0 | 0 | 0 | — | No |
secrets |
Completed | — | — | — | 0 | 21 | — | — | No |
sitemap_surface |
Completed | — | — | — | — | 10 | — | — | No |
ssrf |
Not applicable | — | — | — | — | 0 | — | — | No |
subdomains |
Completed | — | — | — | 0 | 45 | — | — | No |
third_party_surface |
Completed | — | — | — | 0 | 2 | — | — | No |
virtual_hosts |
Completed | — | — | — | 1 | 23 | — | — | No |
xss |
Completed | — | 0 | — | 0 | 0 | 0 | 0 | No |
form_security |
Skipped — no relevant surface | — | — | — | — | 2 | — | — | No |
prototype_pollution |
Skipped — no relevant surface | — | — | — | — | 0 | — | — | No |
Methodology
Non-intrusive external assessment informed by OWASP Top 10 / ASVS. Tested areas:
- DNS & Email — SPF, DMARC, DKIM, DNSSEC, CAA, MTA-STS, dangling records
- TLS / Transport — protocol support, cipher suites, certificate chain and validity
- HTTP Security — security headers, cookies, CORS, cache policy, mixed content
- Application Surface — admin/debug/API endpoints, sensitive files, info disclosure
- Frontend & Source — JavaScript credential patterns, source maps, PWA behaviour
- Redirects & Exposure — parameter redirects, robots/well-known metadata
This report is prepared for the exclusive use of the account that commissioned the assessment. It is based on automated, non-intrusive scanning of publicly accessible systems at the time of the assessment. Findings represent potential security issues identified through validated analysis and should be reviewed by a qualified security professional before remediation decisions are made.
The absence of findings in any category does not imply the absence of risk. This report contains confidential security information; distribution should be limited to authorized personnel.