Back to home
spectrescan_report.pdf

example.com

Scanned July 1, 2026 · 4m 32s · 6 assets discovered

72
risk
6
Assets Found
6
Findings
1
Critical
4m 32s
Scan Time

Findings

6 total
Subdomain Takeover
dev.example.com · Dangling CNAME pointing to unclaimed Heroku backend.
CRITICAL
Exposed .env File
staging.example.com · Environment file accessible at /.env containing database credentials.
HIGH
Missing HSTS Header
example.com · Strict-Transport-Security header absent — allows protocol downgrade.
MEDIUM
Directory Listing Enabled
assets.example.com · Server returns file index at /uploads/ directory.
MEDIUM
Missing CSP Header
example.com · Content-Security-Policy header not set.
MEDIUM
TLS 1.0 Enabled
mail.example.com · Server supports deprecated TLS 1.0 protocol.
MEDIUM

Asset Map

SubdomainIPStatusTech StackFindings
example.com93.184.216.34Livenginx, React3
dev.example.com54.239.28.85LiveNode.js1
staging.example.com54.239.28.86LivePHP 7.41
assets.example.com151.101.1.1LiveS3/CloudFront1
mail.example.com209.85.220.41LivePostfix1
old.example.comDead0

This is a sample report. Run a real scan on your domain.

Scan your domain free →