Website Security Report — Full Example | Soryvex A complete, readable Soryvex security report for a domain we own: the score, what to fix first, every finding, the evidence and the remediation.
Example assessment

A complete Soryvex report, in full.

This is not a mock-up. It is a real assessment of lab.soryvex.com — our own website — run by the same engine that assesses a customer's site and rendered through the same report you get. Every finding, score and severity below is the engine's own output.

Subject
lab.soryvex.com
Risk score
20.3 / 100 · LOW
Confirmed findings
1
Generated
2026-10-08

Regenerated weekly. It is a real run rather than a live one, so the score and findings above are as they stood on that date.

Back to assessments Assessment example-1791466038
External Security Assessment

Security Assessment Report
lab.soryvex.com

Assessment Date
October 08, 2026 at 13:33 UTC
Assessment ID
example-1791466038
Assessed URL
https://lab.soryvex.com
Domain ownership verified — lab.soryvex.com passed DNS TXT verification. Owner-restricted checks were run.

Executive Summary

20.3/ 100
LOW
1Confirmed Findings
0Critical / High
17Observations
7Verified Controls

lab.soryvex.com received a 20.3/100 Low risk rating based exclusively on 1 confirmed security finding. No high or critical severity confirmed findings were identified.

What this score means

Low — No confirmed finding above low severity. Remaining items are hardening opportunities, not an active breach.

  • What set it: The worst confirmed finding here is at this severity. These are hardening gaps: real and worth closing, but they do not on their own put the score in a dangerous band.
  • How it is counted: only confirmed findings move this number. Likely findings add to it but cannot raise it into a band on their own, and observations and verified controls never move it at all. “Confirmed” means Soryvex observed the condition and attached the evidence below — it does not mean the condition was exploited, and this assessment did not attempt to exploit anything.
  • Findings counted: 1 in total, from the confirmed and likely sections of this report.
  • How much of the discovered surface was probed: high confidence — 459 active probe requests against 483 discovered parameters and endpoints. This is a measure of the active testing that was possible, not of the whole assessment.

The score is calculated the same way for every domain, so the same site assessed twice gives the same number. It is a measure of what was exposed from outside, not a measure of everything that could ever go wrong.

Fix these first

Ordered by severity, then by how many assets each one affects. Everything listed here is a finding in this report — the link takes you to it.

  1. LOW

Soryvex AI Analyst Review

AI Analyst unavailable for this assessment.

1 application

Confirmed Findings

Confirmed findings
SeverityFindingConfidenceAffected Asset
LOW Redirect scan unavailable
Affects 1 asset · RED-001
Low https://lab.soryvex.com
low
Redirect scan unavailable
Check RED-001 Confidence Low Category application Affected 1
Why this mattersThis is the class of issue that makes a larger incident easier.
What was observedBase page unreachable (target has no public IP).
Recommended remediationAlways encode/escape user input in responses.
Affected assets https://lab.soryvex.com
Evidence
http_response: https://lab.soryvex.com

Likely Findings

No likely issues were identified during this assessment.

Findings Needing Review

No findings requiring manual review were identified during this assessment.

Potential Issues

Issues that may warrant investigation but could not be conclusively validated with the available evidence.

Potential issues
SeverityFindingConfidenceAffected Asset(s)What was observed
MEDIUM DNSSEC not detected
Affects 1 asset · DNS-008
High lab.soryvex.com DS record absent; DNSSEC validation unavailable.

Security Observations

DNS & Email

DNS-007 CAA record not published — CAA not published; no CA restriction configured.
DNS-030 Common subdomains resolved — Resolved common subdomains: none
DNS-004 DMARC record not published — No _dmarc TXT record; consider publishing one to align mail authentication.
DNS-010 MTA-STS policy not configured — MTA-STS TXT absent; MTA-STS not enforced.
DNS-009 Nameservers missing — No NS records resolved.
EML-013 No BIMI record published — No default._bimi.<domain> TXT record was found. BIMI attaches a brand indicator to mail so receiving clients can show a verified logo; without it, brand impersonation in the inbox…
DNS-006 No MX records published — No MX records found; the domain does not publish an inbound-mail relay. This is not by itself a vulnerability — the domain may not intend to receive mail — but email-security harde…
DNS-005 No common DKIM selectors found — No DKIM TXT records found for common selectors; consider configuring DKIM signing.
DNS-025 No nameservers resolved — No authoritative nameservers were resolved.
DNS-002 SPF record not published — No SPF TXT record found; consider publishing one to define authorized mail senders.
DNS-011 TLS-RPT not configured — TLS reporting TXT absent.

Technology

INFRA-001 Cloudflare CDN detected — The target uses Cloudflare as a CDN or reverse proxy.
INFRA-002 Cloudflare WAF detected — The target appears to be protected by Cloudflare WAF.

Application Surface

AUT-001 Authentication scan unavailable — Base page unreachable (target has no public IP).
SYS-HTTP-FETCH JavaScript scan unavailable — Base page unreachable (target has no public IP).
SYS-HTTP-FETCH Source map scan unavailable — Base page unreachable (target has no public IP).
APP-005 robots.txt is published — Found /robots.txt (1248 bytes).

Verified Controls

DNS & Email

DNS-001Domain resolves correctly
DNS-012No CNAME at zone apex
DNS-029No obvious DNS inconsistencies
DNS-015No wildcard DNS

Application Surface

SRI-001Cross-origin scripts protected by SRI (or none present)
SRI-002Cross-origin stylesheets protected by SRI (or none present)
VHOST-007Host-based routing behaved conventionally

False Positives

No false positives were identified during this assessment.

Not Verifiable & Limitations

CT-001No hostnames found in CT logs — certspotter responded but listed no certificates for this domain.
SYS-MODULE-ERRHTTPS Delivery, HSTS & Certificate Scope: scan incomplete — The module could not complete its assessment because of an internal error. Results for this area are unknown (NOT VERIFIABLE).
Findings are based on passive observation and safe probes; they represent indicators that may require manual validation.
Authenticated/internal application areas requiring valid credentials were not assessed.
Rate limiting and WAF behaviour could not be established from passive evidence where untested.
This assessment is a point-in-time snapshot; security posture changes continuously.

Application Surface Coverage

Coverage-only metrics from the discovery phase. These are inventory statistics and never contribute to the risk score.

Check coverage reconciliation
Check coverageChecks
In Soryvex's check catalog 568
  of which run without ownership verification 245
  of which require verified ownership 323
Withheld from this run for want of ownership verification 0
Distinct checks that reported a finding in this run (a lower bound: a check that ran and found nothing is not counted) 27
Assessed entry point
Assessment targetValue
Submitted URLhttps://lab.soryvex.com
Origin (DNS / TLS / infrastructure scope)https://lab.soryvex.com
Application entry point crawledhttps://lab.soryvex.com
Entry point requestedYes
Entry point fetchedYes (HTTP 200)
Entry point parsed as HTMLYes
Application surface crawlCompleted
Application surface coverage
MetricDiscovered
Pages discovered1
Pages fetched1
Endpoints1
Forms0
Parameters0
Scripts0
API endpoints0
WebSocket endpoints0
Sitemap URLs0
Robots paths0
Requests used (discovery)1116
Crawl limit reachedNo

Discovered vs. Actually Tested

1 endpoint was discovered during application-surface enumeration. This does not mean all of them were security-tested: each security module selects only relevant targets and operates within its configured safe probe limits, and several modules perform passive inspection instead of active probing. Discovery counts are inventory; the "tested / inspected" figures below are what the assessment actually exercised.

Discovered application surface by category
CategoryDiscoveredActually tested / inspected
Pages1—
Endpoints10
Parameters (unique)0—
Parameter/endpoint pairsper module0
Forms00
Scripts00
API candidates00
WebSocket endpoints0—
Active probe requests—459

Fetch pipeline accounting

Where every discovered same-origin target went. A target is discovered once it is recorded in the application-surface inventory, queued when it is admitted to the bounded fetch queue, and fetched/parsed only when its response was a real HTML document. Anything that never reached the parse stage is listed under Rejected with the reason, so a low fetched count is always attributable to a specific cause (target unreachable, non-HTML response, configured cap, budget) rather than being a silent drop. Non-HTML responses are counted separately under Resources fetched and never consume the page budget.

Assessment stages and target counts
StageCount
Application surface crawlCompleted
Entry point fetchedYes
Entry point parsed as HTMLYes
Pages discovered (same-origin inventory)1
Queued for fetch0
Fetch requests issued0
Pages fetched and parsed1
Non-HTML resources fetched0
Rejected (no usable document)0
Skipped — off-origin0
Skipped — duplicate path0
Skipped — request budget exhausted0
Configured crawl limit reachedNo
subdomains no_subdomains_resolved — None of the 45 wordlist names resolved for lab.soryvex.com. Absence of results is not proof that no other subdomain exists; this is a passive wordlist only.
cloud_exposure no_cloud_surface — No cloud storage, CDN or metadata reference was found in the HTML, scripts or configuration that were read.
file_exposure no_sensitive_files — No stack-specific or stack-independent sensitive artifact was reachable. Technologies fingerprinted: cloudflare.
secrets no_secrets_found — No credential-shaped value was found in the HTML, scripts, configuration endpoints or response headers that were read.
ops_exposure no_ops_surface — None of the 60 operations, datastore and orchestration endpoints returned a response attributable to the product itself.
federation_surface no_well_known_documents — None of the 30 conventional well-known paths responded with a document attributable to that product.
sitemap_surface no_sitemap — None of the 10 conventional sitemap locations (nor any sitemap link on the home page or in robots.txt) returned a sitemap document.
content_discovery no_new_paths — None of the 152 wordlist paths differed from this deployment's not-found response (HTTP 404), so no new endpoint was added to the surface.
virtual_hosts no_additional_vhosts — None of the 20 names under lab.soryvex.com returned content distinct from the apex. This does not prove no other virtual host exists; it means none of the common names did.
cms_exposure no_cms_detected — No content management system was fingerprinted from a response header or body, so no CMS-specific paths were probed.
dns_posture no_mail_transport_policy — No MTA-STS or SMTP TLS-RPT record is published, so mail transport security is not enforced or reported.
cors_deep no_cors_target — No HTML page was available to derive cross-origin request endpoints from; the deep CORS checks were skipped.
graphql no_live_graphql — Candidate GraphQL paths did not behave like a GraphQL server.
http_attack_surface no_root_response — The site root did not return a response; routing checks skipped.
websocket_surface no_base_response — Neither the site root nor the assessed entry point could be fetched, so no realtime surface could be discovered.
prototype_pollution no_probe_targets — No query parameter or GET-form input was discovered, so there is no observed request whose query string could be re-parsed into an object. Nothing was invented to probe.
form_security no_pages — No page could be fetched, so no form markup was available to analyse.
third_party_surface no_third_party_markup — This module fetched 2 page(s) and none referenced a script, stylesheet or iframe, so the third-party surface is empty by evidence rather than by assumption. This says nothing about routes outside the pages that were read.
authz no_candidates — Application surface present but no discovered endpoint matches admin, ID-shaped, auth-parameter, POST form, or API criteria.
ssrf no_url_fetch_params — Application surface present but no URL-fetch/webhook-shaped parameters were discovered; SSRF parameter observation skipped.
ssrf no_fetch_urls — Application surface present but no fetch/proxy/import-style URL literals were found in JS fetch/XHR calls; server-side fetch observation skipped.
file_upload no_upload_surface — Application surface present but no discovered form, API route or script reference indicates an upload surface; upload analysis skipped.
injection no_probe_targets — Application surface present but no GET query parameters or GET-form inputs with names were discovered; parameter probing skipped.
xss no_probe_targets — Application surface present but no GET query parameters or GET-form inputs with names were discovered; reflection probing skipped.
path_traversal no_file_parameters — No observed parameter looks like a file/path input on a file-serving endpoint; path-traversal verification skipped.
command_injection no_command_parameters — No observed parameter looks like a shell-input on a diagnostics/tool endpoint; command-injection verification skipped.
parameter_analysis no_parameters — No query parameter or GET-form input was discovered, so parameter handling could not be analysed.
client_data_exposure no_client_data_exposure — 1 script source(s) were analysed for client-side credential storage, personal data, internal routes, embedded operations and build-time configuration; none were present.
api_security no_api_surface — Application surface present but no API endpoints or scripts were discovered by the crawler; API-security analysis used the fetched base page only.

Per-module coverage

One row per security module. "Parameter pairs" counts discovered endpoint+parameter pairs; "Resources inspected" counts passive inspection (scripts/forms); "Active probes" are requests sent against discovered targets. A zero in one column has a specific meaning shown by the module status — for example "Not applicable" (no relevant surface) or "Completed — passive inspection" — and never means the module was skipped. These numbers are coverage metadata and never affect the risk score.

Module coverage notes
ModuleStatusEndpointsParameter pairs Resources inspectedTargets selectedActive probesSkipped (limit) Not relevantFallback
api_security Not applicable 0 — — — 0 — — No
attack_path Completed — — — — 0 — — No
authz Not applicable 0 — — 0 0 0 0 No
client_data_exposure Completed — — — 0 0 — — No
cloud_exposure Completed — — — — 0 — — No
cms_exposure Completed — partial coverage (6/25 tested, 24%) — — — 0 6 — — No
command_injection Not applicable — — — 0 0 0 — No
content_discovery Completed — — — — 153 — — No
cors_deep Completed — — — — 0 — — No
dns_deep Completed — — — 1 1 — — No
dns_posture Completed — — — — 8 — — No
federation_surface Completed — — — 0 30 — — No
file_exposure Completed — — — 0 76 — — No
file_upload Not applicable — — 0 — 0 — — No
graphql Completed — — — — 10 — — No
http_attack_surface Completed — — — — 0 — — No
injection Completed — 0 — 0 0 0 0 No
javascript_deep Completed — — — — 12 — — No
ops_exposure Completed — — — 0 60 — — No
parameter_analysis Completed — — — — 0 — — No
path_traversal Not applicable — — — 0 0 0 — No
secrets Completed — — — 0 21 — — No
sitemap_surface Completed — — — — 10 — — No
ssrf Not applicable — — — — 0 — — No
subdomains Completed — — — 0 45 — — No
third_party_surface Completed — — — 0 2 — — No
virtual_hosts Completed — — — 1 23 — — No
xss Completed — 0 — 0 0 0 0 No
form_security Skipped — no relevant surface — — — — 2 — — No
prototype_pollution Skipped — no relevant surface — — — — 0 — — No

Methodology

Non-intrusive external assessment informed by OWASP Top 10 / ASVS. Tested areas:

  • DNS & Email — SPF, DMARC, DKIM, DNSSEC, CAA, MTA-STS, dangling records
  • TLS / Transport — protocol support, cipher suites, certificate chain and validity
  • HTTP Security — security headers, cookies, CORS, cache policy, mixed content
  • Application Surface — admin/debug/API endpoints, sensitive files, info disclosure
  • Frontend & Source — JavaScript credential patterns, source maps, PWA behaviour
  • Redirects & Exposure — parameter redirects, robots/well-known metadata
Disclaimer

This report is prepared for the exclusive use of the account that commissioned the assessment. It is based on automated, non-intrusive scanning of publicly accessible systems at the time of the assessment. Findings represent potential security issues identified through validated analysis and should be reviewed by a qualified security professional before remediation decisions are made.

The absence of findings in any category does not imply the absence of risk. This report contains confidential security information; distribution should be limited to authorized personnel.