PUBLIC DEMO — anonymized sample data, not a real scan

Full Security Report for

How Scaneo performs the check

Vulnerability correlation
Detected service and product versions are compared against public CVE databases.
Web application security testing
Active tests for injection, XSS, SSRF, misconfiguration and information disclosure.
Network exposure analysis
Mapping of publicly reachable ports and services, including versions and OS identification.
Domain infrastructure & leaks
Checks of DNS/email configuration (SPF, DMARC), subdomains and data breach databases.

Scaneo combines multiple layers of external security testing focused on web applications, network exposure, domain infrastructure and credential leaks. Each method is designed to surface real risk without unnecessary noise.

Vulnerability Score / Business Impact


Overall vulnerability score
Backend
Frontend
Server
Data leaks
Threats

Business Impact Legend


CategoryDescription
NoneNo business impact. This is a recommendation only, not an actual vulnerability.
MinimalLow operational impact; unlikely to affect customers or compliance.
ModeratePotential impact on customers; remediation recommended within the normal release cycle.
SignificantMay disrupt operations or expose sensitive data; remediation needed soon.
SevereThreatens critical business processes or compliance; immediate action required.

Phishing Potential


Phishing potential (highest risk)
DomainHighest-risk phishing domain

Vulnerability Breakdown


Verified
Unverified
Vulnerabilities by CVSS / Severity
Critical
High
Medium
Low
Verified vulnerabilities by area
Unverified vulnerabilities by area

Backend


Total countHighest CVSS
Verified CVSS histogram
Unverified CVSS histogram

Frontend


Total countHighest CVSS
Verified CVSS histogram
Unverified CVSS histogram

Server


Total countHighest CVSS
Verified CVSS histogram
Unverified CVSS histogram

Summary


Vulnerabilities are scored using the CVSS standard and automatically verified wherever possible. Findings cover the full spectrum: the web application, SSL/TLS configuration, access credentials and network services.

🤖

AI remediation prompts are guidance only. Each finding includes a ready-made prompt for Claude, ChatGPT or Cursor. AI suggestions must be reviewed by a qualified developer before being applied. Do not execute AI-generated commands without understanding their impact. Scaneo does not verify AI output.

Verified Vulnerabilities

CVSSNameAssetAreaAction

Unverified Vulnerabilities

CVSSNameAssetAreaAction

In addition to your primary domain, we also check subdomains, SPF & DMARC configuration, WHOIS records, domain takeover risks and lookalike domains used for phishing.

Domains & Subdomains

DomainPhishing riskThreat intelStatus

We identify email addresses associated with your domain and cross-check them against data breach databases to identify compromised accounts and leaked credentials.

Email Addresses

EmailLeaksLeaked passwordsStatus

We check publicly reachable network services and open ports. For each discovered server we identify the operating system, running services and known vulnerabilities.

Note: Findings from scanning an IP address may reflect the infrastructure of a shared hosting provider rather than the customer's application directly. If an IP belongs to a known cloud or hosting provider, vulnerabilities and open ports may be shared with other tenants on the same platform.

Server Infrastructure

IP addressOperating systemOpen servicesAssociated domainsHosting provider

We map publicly accessible paths, files and directories of the target website. We focus on CMS installations, hidden or sensitive files, backup files and misconfigured endpoints. JavaScript libraries are checked for known CVE vulnerabilities.

Potentially Sensitive Paths

⚠ These paths may expose sensitive functionality or files. Review manually whether they should be publicly accessible. Examples: uploads, test, backup, config, admin.

Web file / PathStatus

Forbidden Paths (4xx)

🔒 Paths that returned a 4xx (Forbidden / Unauthorized) response. These paths exist on the server but access was denied — they may indicate hidden admin panels, protected areas or misconfigured access control.

Web file / PathStatus

Error Paths (5xx)

🚨 Paths that returned a 5xx (Server Error) response. These may expose stack traces, debug output or internal error details.

Web file / PathStatus

All Other Web Files

Web file / PathStatus