Sample report
A PDF report after every scan
Each scan produces a PDF with an executive summary and every finding from that scan ranked by severity with its fix. Combine scanners for the port and TLS checks auditors ask for. Schedule scans daily, weekly, or monthly and set who receives the report by email.
The organization, targets, and dates in this sample are examples. The white-label branding is a Professional plan feature.


Inside the PDF
Nine sections from summary to glossary
An executive summary, the risks for each target, one section per scanner, and a glossary. Every risk has a description and a solution, so engineers can work from the PDF without an account.

Executive summary, page 3

Risks by target, page 5

Full risk details, page 9

Network vulnerabilities, page 42
- 1
Executive Summaryp. 3
Totals by severity across every target, what an accepted risk means, and how many risks each scanner found.
- 2
Risks By Targetp. 4
A severity table per target, then every risk grouped by scanner with its threat level and first-detected date.
- 3
Active Web Application Vulnerabilitiesp. 7
OWASP ZAP submits requests and forms to test for SQL injection, remote command execution, XSS, and more.
- 4
Passive Web Application Vulnerabilitiesp. 23
OWASP ZAP inspects pages, requests, and responses for cross-domain misconfigurations, insecure cookies, and vulnerable JS dependencies.
- 5
SSL/TLS Securityp. 41
SSLyze checks for misconfigured or expired certificates, weak ciphers, and vulnerabilities such as Heartbleed.
- 6
Network Vulnerabilitiesp. 42
OpenVAS tests servers and internet-connected devices for over 50,000 vulnerabilities, each scored with CVSS.
- 7
Open TCP Portsp. 46
Nmap scans all 65,535 TCP ports and lists every open one.
- 8
Open UDP Portsp. 49
Nmap checks for open ports on common UDP services.
- 9
Glossaryp. 50
Plain definitions of every term in the report, from accepted risk to threat level.
Sections 3 to 6 end with full details for each risk found: a description, a solution, the targets it affects, and when it was first detected. Sections 7 and 8 list the open ports.
- Prepared by
- ACME MSSP Incorporated
- Generated
- April 28, 2023
- Target
- example.com
- Scanners
- OWASP ZAP, SSLyze, OpenVAS, Nmap
Executive summary, page 3
Totals first so you know where to start
No high risks on this scan. The 14 medium findings are mostly missing security headers and anti-CSRF tokens, plus two weak TLS settings. The 2 accepted risks are the open ports 80 and 443, reviewed by the team and excluded from the counts.
high
0
medium
14
low
17
accepted
2
| Target | High | Medium | Low | Accepted |
|---|---|---|---|---|
| example.com | 0 | 14 | 17 | 2 |
Findings, sections 3 to 6
Each finding and how to fix it
Every finding names the scanner that found it and when it was first detected, with a full description and solution in the PDF. OpenVAS network findings also carry a CVSS score.
| Severity | Finding | Scanner | First detected | CVSS |
|---|---|---|---|---|
| medium | Absence of Anti-CSRF Tokens Add a unique, unpredictable anti-CSRF token to every form, using a vetted library such as OWASP CSRFGuard. | OWASP ZAP (active) | Jan 4, 2023 | |
| medium | Missing Anti-clickjacking Header Set X-Frame-Options to DENY or SAMEORIGIN, or a Content-Security-Policy frame-ancestors directive, on every page. | OWASP ZAP (active) | Feb 13, 2023 | |
| medium | CSP: Wildcard Directive Configure the web server or load balancer to send a Content-Security-Policy header without wildcard sources. | OWASP ZAP (active) | Jan 4, 2023 | |
| medium | CSP: script-src unsafe-inline Configure the Content-Security-Policy header so script-src does not allow unsafe-inline. | OWASP ZAP (active) | Jan 4, 2023 | |
| medium | CSP: style-src unsafe-inline Configure the Content-Security-Policy header so style-src does not allow unsafe-inline. | OWASP ZAP (active) | Jan 4, 2023 | |
| medium | Absence of Anti-CSRF Tokens Add a unique, unpredictable anti-CSRF token to every form, using a vetted library such as OWASP CSRFGuard. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | Cross-Domain Misconfiguration Restrict Access-Control-Allow-Origin to a specific set of domains, or remove the CORS headers so the browser enforces the same-origin policy. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | Application Error Disclosure Serve custom error pages and log the details on the server instead of returning them to the browser. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | Missing Anti-clickjacking Header Set X-Frame-Options to DENY or SAMEORIGIN, or a Content-Security-Policy frame-ancestors directive, on every page. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | CSP: Wildcard Directive Configure the web server or load balancer to send a Content-Security-Policy header without wildcard sources. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | CSP: script-src unsafe-inline Configure the Content-Security-Policy header so script-src does not allow unsafe-inline. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | CSP: style-src unsafe-inline Configure the Content-Security-Policy header so style-src does not allow unsafe-inline. | OWASP ZAP (passive) | Feb 13, 2023 | |
| medium | SSL/TLS: Report Weak Cipher Suites Reconfigure the service so it no longer accepts the listed weak cipher suites. | OpenVAS | Feb 13, 2023 | 5.0 |
| medium | SSL/TLS: Deprecated TLSv1.0 and TLSv1.1 Protocol Detection Disable TLS 1.0 and 1.1 in favor of TLS 1.2 or later. | OpenVAS | Feb 13, 2023 | 4.3 |
The 17 low-severity findings, each with its full description and solution, are in the PDF.
Open ports (Nmap), sections 7 and 8
Two open ports and both accepted
| Target | Port | First detected | Status |
|---|---|---|---|
| example.com | TCP 443 | Feb 13, 2023 | Accepted |
| example.com | TCP 80 | Feb 13, 2023 | Accepted |
SSL/TLS (SSLyze), section 5
No findings from SSLyze
SSLyze checks for misconfigured or expired certificates, weak ciphers, and vulnerabilities such as Heartbleed. It found nothing on example.com. The weak cipher suites and the TLS 1.0 and 1.1 support above come from the OpenVAS network scan.
No risks detected
Free trial
Try it on your own targets
Scan your websites, servers, networks, and APIs with every scanner in the Premium plan.
14 days free. No credit card required.

Speed and power,
without the complexity
The world's leading vulnerability scanners, all in one platform.