← new scan
~/scans/www.cambridgemty.edu.mx.report
⇣ export pdf
target www.cambridgemty.edu.mx
resolved3.162.163.12
scanned 2026-09-04 03:35:01
modules 7 of 7 completed
// overall risk
HIGH Risk
15 issues across 7 modules — 2 high, 6 medium, 7 low
0 critical
2 high
6 medium
7 low
0 ok
01
WHOIS & DNS
DNS records retrieved — email policy issues found
· LOW
// whois

          
// dns records
A none
www no record
MX MISSING
// email security
// findings (5)
  • ok SPF record present
  • · low No DMARC record — email abuse is harder to detect
  • · low No MX records — domain may not be set up for email
  • · low No CAA records — any certificate authority can issue certs for this domain
  • · low Certificate Transparency: 1942 subdomain(s) ever issued certs — 2013.iad.edu.mx, academias.aparicio.edu.mx, acano.cudi.edu.mx, activeenglish.edu.mx, activesync.institutomora.edu.mx, activesync.udem.edu.mx (+1936 more)
02
SSL / TLS Certificate
Valid certificate, expires in 178 days — TLSv1.3
OK
// raw output
issuer Amazon RSA 2048 M04
subject *.cambridgemty.edu.mx
valid from Aug 15 00:00:00 2026 UTC
valid to Feb 28 23:59:59 2027 UTC
tls version TLSv1.3
// findings (3)
  • ok Certificate valid for 178 more days
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 10 plugins found
· LOW
// raw output
platform WordPress
theme astra
plugins 10 detected
plugin.01 astra-addon
plugin.02 bdthemes-prime-slider
plugin.03 bdthemes-prime-slider-lite
plugin.04 elementor
plugin.05 elementor-pro
plugin.06 header-footer-elementor
plugin.07 premium-addons-for-elementor
plugin.08 translatepress-developer
plugin.09 translatepress-multilingual
plugin.10 ultimate-elementor
xmlrpc.php not accessible
login path /wp-login.php (default)
user enum protected
// findings (1)
  • · low Login URL uses default path — consider hiding or rate-limiting
04
Security Headers
7 of 7 headers missing
HIGH
// raw output
HSTS MISSING
CSP MISSING
X-Frame-Options MISSING
X-Content-Type-Options MISSING
Referrer-Policy MISSING
Permissions-Policy MISSING
Cross-Origin-Opener MISSING
// findings (8)
  • medium HSTS not set — browsers may allow HTTP connections
  • high X-Content-Type-Options missing — MIME-sniffing possible
  • high X-Frame-Options missing — clickjacking attacks possible
  • medium Referrer-Policy missing — leaking referrer data to third parties
  • medium Content-Security-Policy missing — site exposed to XSS injection
  • medium Permissions-Policy missing — browser features not restricted
  • · low Cross-Origin-Opener-Policy not set
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/3 · 14 headers · Apache/2.4.68 (Debian)
MEDIUM
// detected
AWS CloudFront Site is fronted by AWS CloudFront — WAF, DDoS protection and CDN caching active
Server version exposed Server header reveals version info (Apache/2.4.68 (Debian)) — remove or mask the version string
HTTP/3 HTTP/3 (QUIC) in use — fastest available protocol, low latency and connection migration
GZIP compression Response is GZIP-compressed — reduces bandwidth usage
// raw headers (14)
status HTTP/3 200
age 1104613
via 1.1 e903d882f1a54699fe2f06a8607b4292.cloudfront.net (CloudFront)
date Sat, 22 Aug 2026 08:44:19 GMT
link <https://www.cambridgemty.edu.mx/wp-json/>; rel="https://api.w.org/", <https://w…
vary Accept-Encoding
server Apache/2.4.68 (Debian)
alt-svc h3=":443"; ma=86400
x-cache Hit from cloudfront
x-amz-cf-id TMWyvGSaQMYvz8YkjlYPketfJ73Md4Sr5X4APruSRnzG3DCvhMoI1Q==
content-type text/html; charset=UTF-8
x-amz-cf-pop ORD56-P8
content-length 47311
content-encoding gzip
// findings (4)
  • ok AWS CloudFront detected (WAF + CDN)
  • medium Server header exposes version: Apache/2.4.68 (Debian)
  • ok HTTP/3 enabled — best available
  • ok GZIP compression active
06
External JS Libraries
1 external script from 1 domain
MEDIUM
// raw output
external scripts 1 from 1 domain(s)
domain widget.botlers.io (1 file)
static /sdk/main.js
sri-missing https://widget.botlers.io/sdk/main.js
// findings (2)
  • ok 1 external script loaded from 1 domain
  • medium No Subresource Integrity (SRI) hashes — a CDN compromise would silently inject malicious code
07
Malware & Blocklists
Clean — not present on any monitored blocklist
OK
// raw output
Google Safe Browsing clean
VirusTotal clean
injected scripts 0 detected
malware patterns 0 matches
// findings (3)
  • ok Google Safe Browsing — clean
  • ok VirusTotal — clean
  • ok No malware signatures found across monitored blocklists
// end of report · www.cambridgemty.edu.mx · 2026-09-04 03:35:01 ↻ scan again