Skip to main content

Sample report

The report you get, filled in for our demo clinic.

It has the same layout and the same kind of findings as the report a verified scan produces. Read the findings and fixes in plain English, then print it or save it as a PDF. No sign-up.

Vantyris · Security hygiene report

VT-2026 · v1.0.0 · Page 01 / 12

Bright Smile Dental

bright-smile-dental.example · Scan date 2026-05-22 14:04 UTC · Verified standard scan

Overall posture

Action required.

Two High findings need attention this week. Two Medium findings should be closed within the month. Five healthy findings, solid TLS & HSTS work.

Executive summary

Your domain has solid TLS and DNS basics. Two things matter this week: nobody can prove an email claiming to be from your clinic is genuine, and there's an admin panel exposed to the open internet on port 8080. Both are fixable in under two hours by your web host.

The fixes are concrete and named below. Forward this report (or its PDF) to whoever maintains your site.

2 High2 Medium5 HealthyMethodology v1.0.0

Findings, in order of severity

  1. 01

    Missing DMARC policy

    high

    Your booking-system domain has no DMARC record. Anyone can send email that looks like it came from your clinic, and the recipient's mail server has no way to tell it's fake. It's also one of the cheapest fixes in this report.

    How to fix

    Ask your domain registrar (or use your web host's DNS panel) to add a TXT record at _dmarc.bright-smile-dental.example with the value v=DMARC1; p=quarantine; rua=mailto:dmarc@bright-smile-dental.example.

    Owner: your DNS administrator · Time-to-fix: ~ 30 min

    ▸ Show technical evidence

    DNS lookup of _dmarc.bright-smile-dental.example returned NXDOMAIN.

  2. 02

    Public admin panel on port :8080

    high

    A WordPress admin panel is reachable from the public internet on port 8080. Anyone can try to log in, or look for known exploits in an old version. A production site should have it firewalled off.

    How to fix

    Ask your web host to firewall port 8080 to allow only your office IP, or restrict access with HTTP Basic Auth at the host level. If you don't recognise the service, ask the host whether it's needed.

    Owner: your web host · Time-to-fix: ~ 1 hr

    ▸ Show technical evidence

    Open port 8080 (HTTP) responding with WordPress login page at /wp-admin.

  3. 03

    Missing Content-Security-Policy

    medium

    Your site sends no Content-Security-Policy header. CSP is the browser's standard defence against cross-site scripting. Without it, if a flaw ever turns up in your site's code, an attacker has an easier time running scripts in your visitors' browsers.

    How to fix

    Add a CSP header at your host (Cloudflare → Transform Rules → Modify Response Headers, or through your hosting panel). Run it as Content-Security-Policy-Report-Only for a week first, then enforce it.

    Owner: your developer · Time-to-fix: ~ 1 hr + 1 week monitoring

    ▸ Show technical evidence

    GET / returned no Content-Security-Policy response header.

  4. 04

    SSL Labs grade B, TLS 1.0 still enabled

    medium

    Your TLS setup is mostly modern, but TLS 1.0, a protocol from 1999, is still switched on. It's formally deprecated and every major browser has dropped it. Leaving it on costs you a little on your security score and leaves a small risk in place.

    How to fix

    At your hosting panel (or Cloudflare's TLS settings → Minimum TLS Version), set the minimum TLS version to 1.2. Modern clients will not notice.

    Owner: your web host · Time-to-fix: ~ 5 min

    ▸ Show technical evidence

    SSL Labs assessment returned grade B with the note 'This server supports TLS 1.0.'

What's healthy

  • TLS 1.3 supported with strong cipher suites
  • HSTS header present (max-age = 1 year)
  • DNS resolution stable across multiple regions
  • No exposed database services on common ports (3306, 5432, 27017)
  • Cookies set with the Secure and HttpOnly attributes
Vantyris · JAMRA STUDIOS LTD · UK / EUMethodology v1.0.0 · 2026Page 12 / 12, End
Run a real scan

Now do yours.

Free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40.