Back to homeCRITICALHIGHMEDIUMMEDIUMMEDIUMMEDIUM
spectrescan_report.pdf
example.com
Scanned July 1, 2026 · 4m 32s · 6 assets discovered
72
risk
6
Assets Found
6
Findings
1
Critical
4m 32s
Scan Time
Findings
6 totalSubdomain Takeover
dev.example.com · Dangling CNAME pointing to unclaimed Heroku backend.
Exposed .env File
staging.example.com · Environment file accessible at /.env containing database credentials.
Missing HSTS Header
example.com · Strict-Transport-Security header absent — allows protocol downgrade.
Directory Listing Enabled
assets.example.com · Server returns file index at /uploads/ directory.
Missing CSP Header
example.com · Content-Security-Policy header not set.
TLS 1.0 Enabled
mail.example.com · Server supports deprecated TLS 1.0 protocol.
Asset Map
| Subdomain | IP | Status | Tech Stack | Findings |
|---|---|---|---|---|
| example.com | 93.184.216.34 | Live | nginx, React | 3 |
| dev.example.com | 54.239.28.85 | Live | Node.js | 1 |
| staging.example.com | 54.239.28.86 | Live | PHP 7.4 | 1 |
| assets.example.com | 151.101.1.1 | Live | S3/CloudFront | 1 |
| mail.example.com | 209.85.220.41 | Live | Postfix | 1 |
| old.example.com | — | Dead | — | 0 |
This is a sample report. Run a real scan on your domain.
Scan your domain free →