Security Report
Moderate postureSecurity Score
82/100
composite severity
Assets Discovered
143
subdomains + endpoints
Live Hosts
37
responding to probes
Technologies Found
18
fingerprinted stacks
Findings
12
across all severities
AI Analysis
Executive Summary
PhantomRed discovered exposed assets across the attack surface. Several medium-risk findings require review, including outdated technologies and exposed endpoints. One critical issue — an unauthenticated admin interface — should be remediated first, followed by the exposed development host and outdated server software. Overall posture is moderate; prioritising the critical and high findings would meaningfully reduce exploitable surface.
Findings
12 total · top 4 shown
CRITICAL
Exposed Admin Interface
Affected
admin.demo.phantomred.comEvidence
HTTP 200 response detected on admin panel with no authentication challenge.
Recommendation
Restrict access by source IP and enforce authentication on the admin interface immediately.
HIGH
Exposed Development Host
Affected
dev.demo.phantomred.comEvidence
Publicly reachable development environment returning verbose error output.
Recommendation
Move development hosts behind a VPN or IP allow-list and disable verbose errors in non-production.
MEDIUM
Outdated Server Software
Affected
api.demo.phantomred.comEvidence
Server banner reports an outdated web server version with known advisories.
Recommendation
Upgrade the web server to a supported release and suppress version disclosure in response headers.
LOW
Missing Security Headers
Affected
demo.phantomred.comEvidence
Responses missing
Content-Security-Policy and X-Frame-Options headers.Recommendation
Add standard security response headers to reduce clickjacking and content-injection risk.
Attack Surface
Observed hosts| Host | Status | Technology | Risk |
|---|---|---|---|
| api.demo.phantomred.com | live | nginx · Node.js | medium |
| admin.demo.phantomred.com | live | Apache · PHP | high |
| dev.demo.phantomred.com | live | Express · staging | high |
| cdn.demo.phantomred.com | live | Cloudflare | low |
How This Report Was Generated
Workflow visibility
Subfinder
HTTPX
Nuclei
AI Analysis
Report
Each stage feeds the next — build your own chain in the Workflow Generator, or explore Nuclei automation and autonomous recon workflows.
Available Exports
Output formats PDF Report .pdf
JSON .json
CLI Output stdout