← new scan
~/scans/creation.green-alpaga.fr.report
⇣ export pdf
target creation.green-alpaga.fr
resolved51.158.60.36
scanned 2026-09-10 13:25:58
modules 7 of 7 completed
// overall risk
MEDIUM Risk
8 issues across 7 modules — 4 medium, 4 low
0 critical
0 high
4 medium
4 low
0 ok
01
WHOIS & DNS
DNS records retrieved — SPF & DMARC present
· LOW
// whois
registrar NETIM
created 2026-04-21
expires 2027-04-21
updated 2026-04-28
nameserver ns1.hosterra.eu
nameserver ns2.hosterra.eu
status client transfer prohibited
// dns records
A 51.158.60.36
AAAA 2001:bc8:1201:724:b683:51ff:fe06:ae68
www A 51.158.60.36
www AAAA 2001:bc8:1201:724:b683:51ff:fe06:ae68
MX MISSING
NS ns1.hosterra.eu
NS ns2.hosterra.eu
// ip whois (1)
51.158.60.36 SSL unavailable for this endpoint, order a key at https://members.ip-api.com/ whois ↗
// lookup on dnsarchive.net
// email security
// txt records (1)
txt.01 google-site-verification=q4IivUi5xS-YZ04452A4iG66hlxi6wrultFiIJdhZHs
// findings (5)
  • ok SPF record present
  • ok DMARC record present
  • · low No MX records — domain may not be set up for email
  • ok CAA records present (1): letsencrypt.org
  • · low Certificate Transparency: 1 subdomain(s) ever issued certs — green-alpaga.fr
// detected services (1)
02
SSL / TLS Certificate
Valid certificate, expires in 66 days — TLSv1.3
OK
// raw output
issuer YR1
subject creation.green-alpaga.fr
valid from Aug 17 07:29:41 2026 UTC
valid to Nov 15 07:29:40 2026 UTC
tls version TLSv1.3
// findings (3)
  • ok Certificate valid for 66 more days
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 1 plugins found
OK
// raw output
platform WordPress
theme kadence
plugins 1 detected
plugin.01 elementor
xmlrpc.php not accessible
login path /wp-login.php
user enum protected
// findings (1)
  • ok WordPress hardening looks reasonable
04
Security Headers
All 7 security headers present
MEDIUM
// raw output
HSTS ok (max-age=15768000; includeSubDomains)
CSP ok (upgrade-insecure-requests;)
X-Frame-Options ok (SAMEORIGIN)
X-Content-Type-Options ok (nosniff)
Referrer-Policy ok (strict-origin-when-cross-origin)
Permissions-Policy ok (accelerometer=(), autoplay=(), camera=())
Cross-Origin-Opener ok (unsafe-none)
// findings (12)
  • ok Referrer-Policy is configured
  • ok X-Frame-Options is configured
  • ok Permissions-Policy is configured
  • ok X-Content-Type-Options is configured
  • ok Content-Security-Policy is configured
  • ok Strict-Transport-Security is configured
  • ok Cross-Origin-Opener-Policy is configured
  • medium CSP weakness — no default-src or script-src — falls back to permissive defaults
  • medium CSP weakness — no frame-ancestors — clickjacking only protected by X-Frame-Options
  • medium CSP weakness — no object-src — should be set to 'none'
  • medium CSP weakness — no base-uri — base tag injection unrestricted
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/1.1 · 21 headers · nginx
· LOW
// detected
nginx Web server: nginx
HTTP/1.1 HTTP/1.1 detected — upgrade to HTTP/2 for significantly better performance and security
Brotli compression Response is Brotli-compressed — best compression ratio for text content
// raw headers (21)
status HTTP/1.1 200
date Thu, 10 Sep 2026 13:25:48 GMT
server nginx
alt-svc h3=":443"; ma=86400
connection keep-alive
x-hosted-by Hosterra
content-type text/html; charset=UTF-8
x-cache-status STALE
referrer-policy strict-origin-when-cross-origin
x-frame-options SAMEORIGIN
content-encoding br
carbontxt-location https://hosterra.eu/.well-known/carbon.txt
permissions-policy accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capt…
x-content-type-options nosniff
content-security-policy upgrade-insecure-requests;
strict-transport-security max-age=15768000; includeSubDomains
cross-origin-opener-policy unsafe-none
access-control-allow-headers Content-Type, Authorization
access-control-allow-methods GET,POST
cross-origin-resource-policy cross-origin
x-permitted-cross-domain-policiesnone
// findings (3)
  • ok Web server: nginx
  • · low HTTP/1.1 in use — HTTP/2 or HTTP/3 recommended
  • ok Brotli (br) compression active
06
External JS Libraries
No external JS libraries detected
OK
// raw output
external scripts 0 detected
// findings (1)
  • ok No third-party JavaScript files loaded
07
Malware & Blocklists
Clean — not present on any monitored blocklist
OK
// raw output
Google Safe Browsing clean
VirusTotal clean
injected scripts 0 detected
malware patterns 0 matches
// findings (3)
  • ok Google Safe Browsing — clean
  • ok VirusTotal — clean
  • ok No malware signatures found across monitored blocklists
// end of report · creation.green-alpaga.fr · 2026-09-10 13:25:58 ↻ scan again