← new scan
~/scans/dsm.edu.ni.report
⇣ export pdf
target dsm.edu.ni
resolved162.248.49.18
scanned 2026-09-08 17:45:00
modules 7 of 7 completed
// overall risk
HIGH Risk
15 issues across 7 modules — 2 high, 7 medium, 6 low
0 critical
2 high
7 medium
6 low
0 ok
01
WHOIS & DNS
DNS records retrieved — email policy issues found
MEDIUM
// whois

          
// dns records
A none
www no record
MX MISSING
// email security
// findings (4)
  • medium No SPF record — email spoofing is possible
  • · low No DMARC record — email abuse is harder to detect
  • · low No MX records — domain may not be set up for email
  • · low No CAA records — any certificate authority can issue certs for this domain
02
SSL / TLS Certificate
Valid certificate, expires in 67 days — TLSv1.3
OK
// raw output
issuer YR1
subject www.dsm.edu.ni
valid from Aug 17 01:47:46 2026 UTC
valid to Nov 15 01:47:45 2026 UTC
tls version TLSv1.3
// findings (3)
  • ok Certificate valid for 67 more days
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 9 plugins found
MEDIUM
// raw output
platform WordPress
theme astra
plugins 9 detected
plugin.01 ays-popup-box
plugin.02 elementor
plugin.03 essential-addons-for-elementor-lite
plugin.04 everest-forms
plugin.05 header-footer-elementor
plugin.06 megamenu
plugin.07 sticky-chat-widget
plugin.08 testimonials-carousel-elementor
plugin.09 the-events-calendar
xmlrpc.php exposed
login path /wp-login.php
user enum protected
// findings (1)
  • medium XML-RPC endpoint is publicly accessible
04
Security Headers
7 of 7 headers missing
HIGH
// raw output
HSTS MISSING
CSP MISSING
X-Frame-Options MISSING
X-Content-Type-Options MISSING
Referrer-Policy MISSING
Permissions-Policy MISSING
Cross-Origin-Opener MISSING
// findings (8)
  • medium HSTS not set — browsers may allow HTTP connections
  • high X-Content-Type-Options missing — MIME-sniffing possible
  • high X-Frame-Options missing — clickjacking attacks possible
  • medium Referrer-Policy missing — leaking referrer data to third parties
  • medium Content-Security-Policy missing — site exposed to XSS injection
  • medium Permissions-Policy missing — browser features not restricted
  • · low Cross-Origin-Opener-Policy not set
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/3 · 9 headers · Apache
MEDIUM
// detected
Apache Web server: Apache
HTTP/3 HTTP/3 (QUIC) in use — fastest available protocol, low latency and connection migration
Cookie flags missing 1 of 1 cookie(s) missing security flags
// raw headers (9)
status HTTP/3 200
date Tue, 08 Sep 2026 17:44:23 GMT
link <https://dsm.edu.ni/wp-json/>; rel="https://api.w.org/", <https://dsm.edu.ni/wp-…
server Apache
set-cookie pll_language=es; expires=Wed, 08-Sep-2027 17:44:23 GMT; Max-Age=31536000; path=/…
content-type text/html; charset=UTF-8
x-tec-api-root https://dsm.edu.ni/wp-json/tribe/events/v1/
x-tec-api-origin https://dsm.edu.ni
x-tec-api-version v1
// findings (4)
  • ok Web server: Apache
  • ok HTTP/3 enabled — best available
  • · low No response compression detected — consider enabling GZIP or Brotli
  • medium Cookie pll_language (missing: HttpOnly)
06
External JS Libraries
No external JS libraries detected
OK
// raw output
external scripts 0 detected
// findings (1)
  • ok No third-party JavaScript files loaded
07
Malware & Blocklists
Clean — not present on any monitored blocklist
OK
// raw output
Google Safe Browsing clean
VirusTotal clean
injected scripts 0 detected
malware patterns 0 matches
// findings (3)
  • ok Google Safe Browsing — clean
  • ok VirusTotal — clean
  • ok No malware signatures found across monitored blocklists
// end of report · dsm.edu.ni · 2026-09-08 17:45:00 ↻ scan again