← new scan
~/scans/anchor.host.report
⇣ export pdf
target anchor.host
resolved162.159.134.42
scanned 2026-07-12 14:29:25
modules 7 of 7 completed
// overall risk
CRITICAL Risk
12 issues across 7 modules — 1 critical, 1 high, 5 medium, 5 low
1 critical
1 high
5 medium
5 low
0 ok
01
WHOIS & DNS
DNS records retrieved — SPF & DMARC present
· LOW
02
SSL / TLS Certificate
Valid certificate, EXPIRED — TLSv1.3
CRITICAL
// raw output
issuer WE1
subject anchor.host
valid from May 27 22:15:59 2026 UTC
valid to Aug 25 23:15:55 2026 UTC
tls version TLSv1.3
// findings (3)
  • critical Certificate has expired
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 3 plugins found
OK
04
Security Headers
6 of 7 headers missing
HIGH
// raw output
HSTS MISSING
CSP MISSING
X-Frame-Options MISSING
X-Content-Type-Options ok (nosniff)
Referrer-Policy MISSING
Permissions-Policy MISSING
Cross-Origin-Opener MISSING
// findings (8)
  • medium HSTS not set — browsers may allow HTTP connections
  • high X-Frame-Options missing — clickjacking attacks possible
  • medium Referrer-Policy missing — leaking referrer data to third parties
  • medium Content-Security-Policy missing — site exposed to XSS injection
  • medium Permissions-Policy missing — browser features not restricted
  • · low Cross-Origin-Opener-Policy not set
  • ok X-Content-Type-Options is configured
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/3 · 19 headers · cloudflare
OK
06
External JS Libraries
1 external script from 1 domain
MEDIUM
07
Malware & Blocklists
Clean — not present on any monitored blocklist
OK
// end of report · anchor.host · 2026-07-12 14:29:25 ↻ scan again