Skip to main content
Back to Audits • REF: sample-previ Sample Preview Data
Cybersecurity Perimeter Audit Oct 8, 2026

example-business.com

Point-in-time assessment of the public pages and tools listed below. Findings, measured checks, and tool limitations are reported separately.

Target URL: https://example-business.com
Pages Scanned: 18
84 Out of 100
B Security Health Score
38 of 42 evaluated checkpoints passed
Total Checks 42
Passed Checks 38
Critical / High 1
Moderate / Warnings 2
Low / Info 1
Perimeter Checkpoint Verification: 90% Pass Rate

Category Scorecard & Pillar Breakdown

Security & Response Headers Moderate
82% 10/12 passed

Missing Content-Security-Policy & HSTS headers

Technical Crawlability & SEO Optimal
92% 12/16 passed

Optimal indexation

Speed & Core Web Vitals Fast
90% 8/8 passed

Low TTFB across edge

Accessibility & Semantics Notice
88% 8/9 passed

4 image elements missing descriptive alt tags

Prioritized Audit Findings & Developer Remediation

Prioritized by severity with observed evidence and suggested remediation. Review example configuration against your deployment before use.

find-csp-1 high security Source: headers

Missing Content-Security-Policy (CSP) Header

https://example-business.com/

Security & SEO Impact: Vulnerable to inline Cross-Site Scripting (XSS) and unauthorized third-party script injection.

Show Measured Scanner Evidence
HTTP response headers inspected across all pages; Content-Security-Policy header is absent.
HTTP Add Content-Security-Policy HTTP response header:
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'none'; base-uri 'self'; form-action 'self';

Direction: Add Header set Content-Security-Policy with strict script-src and object-src directives.

find-dmarc-1 medium security Source: dns

DMARC Policy Set to Permissive Mode (p=none)

https://example-business.com/

Security & SEO Impact: Allows phishers and spoofers to send emails appearing from your domain without rejection by recipient mailboxes.

Show Measured Scanner Evidence
DNS TXT record query for _dmarc returned: 'v=DMARC1; p=none; sp=none'.
TXT Update DNS TXT record for _dmarc:
v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc-reports@example-business.com

Direction: Upgrade DMARC policy from p=none to p=quarantine or p=reject.

find-hsts-1 medium security Source: headers

Missing HTTP Strict Transport Security (HSTS)

https://example-business.com/

Security & SEO Impact: Allows man-in-the-middle attackers to downgrade HTTPS connections to unencrypted HTTP.

Show Measured Scanner Evidence
Strict-Transport-Security header was not detected in edge response.
HTTP Add HSTS response header:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Direction: Configure HSTS with max-age=63072000; includeSubDomains; preload in web server or Cloudflare SSL/TLS rules.

find-xcto-1 low security Source: headers

Missing X-Content-Type-Options: nosniff

https://example-business.com/

Security & SEO Impact: Allows browsers to MIME-sniff response types away from declared content-type.

Show Measured Scanner Evidence
Header absent from observed HTTP response.
HTTP Add X-Content-Type-Options header:
X-Content-Type-Options: nosniff

Direction: Deploy X-Content-Type-Options: nosniff header.

Full technical report

The same in-depth sections as the PDF: 4 grouped issues, 6 checkpoints, and 4 page profiles.

Audit at a glance

4 unique issue groups · 4 recorded occurrences. Repeated detections are consolidated into issues; occurrences remain evidence records.

Charts summarize reported evidence, not proof that unreported issues are absent. Only in-scope categories are shown.

Category scores

CategoryScore (0–100)Measured checksUnverified checksPassed / planned
Security & Response Headers82/100Security & Response Headers: 82 of 1002010/12
Technical Crawlability & SEO92/100Technical Crawlability & SEO: 92 of 1003012/16
Speed & Core Web Vitals90/100Speed & Core Web Vitals: 90 of 100108/8
Accessibility & Semantics88/100Accessibility & Semantics: 88 of 100008/9

Measured checks include passed and failed outcomes. Scores reflect the report scoring method; check coverage is shown separately.

Severity distribution

Unique issues by severity: critical 0, high 1, medium 2, low 1, info 04unique issues
SeverityUnique issuesRecorded occurrences
critical0critical: 0 unique issues0
high1high: 1 unique issues1
medium2medium: 2 unique issues2
low1low: 1 unique issues1
info0info: 0 unique issues0

The ring shows the share of unique issues by severity. Bar lengths compare unique issue counts. Occurrences include repeated observations and are not additional unique issues.

Most repeated issues
IssueOccurrencesAffected URLs
Missing Content-Security-Policy (CSP) Header
security · high
1Missing Content-Security-Policy (CSP) Header: 1 occurrences1
DMARC Policy Set to Permissive Mode (p=none)
security · medium
1DMARC Policy Set to Permissive Mode (p=none): 1 occurrences1
Missing HTTP Strict Transport Security (HSTS)
security · medium
1Missing HTTP Strict Transport Security (HSTS): 1 occurrences1
Missing X-Content-Type-Options: nosniff
security · low
1Missing X-Content-Type-Options: nosniff: 1 occurrences1

Top 4 of 4 groups, ranked by recorded occurrences. Repetition does not imply higher severity.

Page issue heatmap

PageSecurity & Response HeadersTechnical Crawlability & SEOSpeed & Core Web VitalsAccessibility & Semantics
https://example-business.com/4
high
000
https://example-business.com/about0000
https://example-business.com/contact0000
https://example-business.com/services0000

Showing 4 of 4 URLs with the highest unique issue burden. Each cell counts unique groups once per URL, including repeated page observations. Color and text indicate the highest severity. 0 means no reported findings, not a passed check. Categories outside the audit scope are omitted.

Remediation roadmap

Phase 1 — Immediate (0–7 days)

Critical and high-severity issues that expose users or block search and availability.

  • F-01 high Missing Content-Security-Policy (CSP) Header · 1 page(s) · effort Low

Phase 2 — Short term (within 30 days)

Medium-severity hardening, accessibility barriers, and search-visibility gaps.

  • F-02 medium DMARC Policy Set to Permissive Mode (p=none) · 1 page(s) · effort Low
  • F-03 medium Missing HTTP Strict Transport Security (HSTS) · 1 page(s) · effort Low

Phase 3 — Planned (within 90 days)

Low-severity improvements and best-practice alignment.

  • F-04 low Missing X-Content-Type-Options: nosniff · 1 page(s) · effort Low

Ongoing — Review and monitor

Informational observations, manual-review items, and re-testing after each release.

No issues in this phase.

Checkpoint results

Unverified means the supporting tool did not complete or evidence was insufficient; it never counts as a pass.

AreaCheckpointOutcomeWhat a pass means
security Strict HTTPS Encryption Across All Pages passed All visited pages enforce HTTPS encryption with valid TLS 1.3 certificates.
security Clickjacking Defense (X-Frame-Options: DENY) passed Valid framing restriction stops hostile iframe overlay attacks.
seo Robots.txt Directive Hygiene passed Clean robots.txt file cleanly guides search bots without blocking valid indexable routes.
seo XML Sitemap Availability & Hygiene passed Sitemap is declared and contains valid indexable 200 URLs.
seo Unique Page Title Tags (< 60 Characters) passed Target pages define clear, non-duplicate titles under 60 characters.
performance Server Response Time & Fast TTFB passed Initial edge time-to-first-byte measured under 320ms.

Security posture

Findings
0 critical · 1 high · 2 medium · 1 low · 0 info
Pages served over HTTPS
4 of 4
Pages with all 8 core security headers
0 of 4
Pages with insecure resource references
0 of 4
Client-side libraries detected
none
Third-party script hosts
fonts.gstatic.com, www.googletagmanager.com
HeaderCoverageObserved (sample)Purpose & recommendation
strict-transport-security 4/4 max-age=31536000 Forces browsers to use HTTPS for the host and blocks SSL-stripping attacks.
Recommended: max-age=31536000; includeSubDomains (add preload after verifying every subdomain).
content-security-policy 0/4 not observed Restricts where scripts, styles, frames, and connections may load from; the main XSS mitigation.
Recommended: default-src 'self'; script-src with nonces or hashes; object-src 'none'; base-uri 'self'; frame-ancestors 'self'.
x-content-type-options 4/4 nosniff Stops MIME sniffing so responses are only interpreted as their declared type.
Recommended: nosniff
x-frame-options 0/4 not observed Legacy clickjacking defense; superseded by CSP frame-ancestors.
Recommended: DENY or SAMEORIGIN (and CSP frame-ancestors).
referrer-policy 4/4 strict-origin-when-cross-origin Controls how much of the URL is sent to other sites in the Referer header.
Recommended: strict-origin-when-cross-origin
permissions-policy 0/4 not observed Disables powerful browser features (camera, microphone, geolocation) the site does not use.
Recommended: camera=(), microphone=(), geolocation=(), payment=()
cross-origin-opener-policy 0/4 not observed Isolates the browsing context from cross-origin windows (Spectre-class and tab-nabbing defenses).
Recommended: same-origin (or same-origin-allow-popups when OAuth popups are used).
cross-origin-resource-policy 0/4 not observed Prevents other origins from embedding the resource.
Recommended: same-origin for private resources; same-site or cross-origin only where needed.
cross-origin-embedder-policy 0/4 not observed Required for cross-origin isolation; only needed for advanced APIs such as SharedArrayBuffer.
Recommended: require-corp when cross-origin isolation is needed; otherwise optional.
cache-control 0/4 not observed Controls browser and CDN caching of the HTML document.
Recommended: Use no-store for personalized pages; short max-age with revalidation for public HTML.

4 grouped issue(s) in this area — see grouped findings below.

Search visibility & technical SEO

Findings
0 critical · 0 high · 0 medium · 0 low · 0 info
Pages with a title of 15–60 characters
4 of 4
Pages with a 50–160 character description
0 of 4
Pages with a self-referencing canonical
4 of 4
Pages with exactly one H1
4 of 4
Pages with a mobile viewport
4 of 4
Pages with Open Graph title and image
0 of 4
Pages declaring a language
4 of 4
Median visible word count
775
PageTitleDesc.CanonicalH1WordsLangViewportOGJSON-LD
https://example-business.com/ 27 29 self 1 640 en yes no —
https://example-business.com/services 43 29 self 1 730 en yes no —
https://example-business.com/about 31 26 self 1 820 en yes no —
https://example-business.com/contact 30 28 self 1 910 en yes no —

0 grouped issue(s) in this area — see grouped findings below.

Performance & reliability

Findings
0 critical · 0 high · 0 medium · 0 low · 0 info
Median time to first byte
240 ms
Slowest time to first byte
300 ms
Median full load
2100 ms
Average page weight
1021 KiB
Heaviest page
1240 KiB
Average requests per page
47
Pages over HTTP/2 or HTTP/3
4 of 4
Pages with console errors
0 of 4
PageTTFBDOM readyLoadKiBRequestsProtocol3rd-party hostsConsole errors
https://example-business.com/ 180 ms 900 ms 1800 ms 801 38 h2 2 —
https://example-business.com/services 220 ms 1020 ms 2000 ms 947 44 h2 2 —
https://example-business.com/about 260 ms 1140 ms 2200 ms 1094 50 h2 2 —
https://example-business.com/contact 300 ms 1260 ms 2400 ms 1240 56 h2 2 —

0 grouped issue(s) in this area — see grouped findings below.

Accessibility

Findings
0 critical · 0 high · 0 medium · 0 low · 0 info
Pages with images missing alt
1 of 4
Pages with skipped heading levels
0 of 4
Pages with unlabeled form fields
0 of 4
Pages with links lacking text
0 of 4
Pages declaring a language
4 of 4
PageLangMissing altSkipped headingsUnlabeled fieldsLinks without text
https://example-business.com/ en 0 0 — —
https://example-business.com/services en 0 0 — —
https://example-business.com/about en 2 0 — —
https://example-business.com/contact en 0 0 — —

0 grouped issue(s) in this area — see grouped findings below.

Grouped findings with affected pages

F-01 high security · headers · 1 page(s) · 1 occurrence(s) · effort Low · Immediate (0–7 days)

Missing Content-Security-Policy (CSP) Header

HTTP response headers inspected across all pages; Content-Security-Policy header is absent.

Recommended action: Add Header set Content-Security-Policy with strict script-src and object-src directives.

Verify the fix: Request the page (`curl -sI https://…`) and confirm the corrected header on every affected URL.

Affected URLs (1)
  • https://example-business.com/
F-02 medium security · dns · 1 page(s) · 1 occurrence(s) · effort Low · Short term (within 30 days)

DMARC Policy Set to Permissive Mode (p=none)

DNS TXT record query for _dmarc returned: 'v=DMARC1; p=none; sp=none'.

Recommended action: Upgrade DMARC policy from p=none to p=quarantine or p=reject.

Verify the fix: Query the record after DNS propagation (for example `dig TXT _dmarc.r5.industries`) and confirm the new value.

Affected URLs (1)
  • https://example-business.com/
F-03 medium security · headers · 1 page(s) · 1 occurrence(s) · effort Low · Short term (within 30 days)

Missing HTTP Strict Transport Security (HSTS)

Strict-Transport-Security header was not detected in edge response.

Recommended action: Configure HSTS with max-age=63072000; includeSubDomains; preload in web server or Cloudflare SSL/TLS rules.

Verify the fix: Request the page (`curl -sI https://…`) and confirm the corrected header on every affected URL.

Affected URLs (1)
  • https://example-business.com/
F-04 low security · headers · 1 page(s) · 1 occurrence(s) · effort Low · Planned (within 90 days)

Missing X-Content-Type-Options: nosniff

Header absent from observed HTTP response.

Recommended action: Deploy X-Content-Type-Options: nosniff header.

Verify the fix: Request the page (`curl -sI https://…`) and confirm the corrected header on every affected URL.

Affected URLs (1)
  • https://example-business.com/

Methodology & scoring

ToolStandardOutcomeFindingsScope
playwright
Headless Chromium crawl of every in-scope page: status, metadata, headings, links, security headers, timing, resource weight, console errors, and client-side libraries.
Browser-observed evidence completed 0 18 pages observed; 0 pages failed; bounded crawl, no authenticated paths or active attacks.
robots.txt
Crawler directives, site-wide blocking, and sitemap references.
RFC 9309 completed 0 Bounded robots inventory observed; sitemap directives sampled.
sitemap.xml
XML sitemap inventory used to seed page discovery.
sitemaps.org protocol completed 0 1 bounded sitemap document observed; 18 same-origin URLs queued before crawling.
  • Each in-scope checkpoint passes only when its tool completed and the observed evidence supports a pass; missing or partial measurements count as unverified, never as passed.
  • Findings that do not map to a checkpoint add to the number of considered checks.
  • The overall score averages the checkpoint pass rate with a severity-weighted deduction (critical 14, high 7, medium 3.5, low 1.2 points; capped per severity). Partial coverage deducts 3 points.
  • Performance-only audits use the mean Lighthouse lab performance score of the sampled pages.
  • Grades: A+ ≥ 97, A ≥ 93, A− ≥ 90, B+ ≥ 87, B ≥ 83, B− ≥ 80, C+ ≥ 77, C ≥ 73, C− ≥ 70, D ≥ 60, F < 60.
  • Lighthouse and PageSpeed Insights lab scores are single-run measurements; real-user data from the Chrome UX Report can differ.

Page-by-page detail

P-01 https://example-business.com/ HTTP 200 · 4 issue(s)
Title
Home — example-business.com (27 chars)
Description length
29 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
640
Language
en
TTFB
180 ms
Load
1800 ms
Transferred
801 KiB
Requests
38
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-02 https://example-business.com/services HTTP 200 · 0 issue(s)
Title
Services & Solutions — example-business.com (43 chars)
Description length
29 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
730
Language
en
TTFB
220 ms
Load
2000 ms
Transferred
947 KiB
Requests
44
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-03 https://example-business.com/about HTTP 200 · 0 issue(s)
Title
About Us — example-business.com (31 chars)
Description length
26 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
820
Language
en
TTFB
260 ms
Load
2200 ms
Transferred
1094 KiB
Requests
50
Protocol
h2
Images / missing alt
8 / 2
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-04 https://example-business.com/contact HTTP 200 · 0 issue(s)
Title
Contact — example-business.com (30 chars)
Description length
28 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
910
Language
en
TTFB
300 ms
Load
2400 ms
Transferred
1240 KiB
Requests
56
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

Glossary

CSP
A response header (Content-Security-Policy) that limits which sources may run scripts or load content.
HSTS
HTTP Strict Transport Security: tells browsers to use HTTPS only for a host.
TLS
Transport Layer Security: the encryption protocol behind HTTPS.
SPF / DKIM / DMARC
Email authentication standards that stop others from sending mail as your domain.
CAA
DNS record naming the certificate authorities allowed to issue certificates for the domain.
DNSSEC
Cryptographic signing of DNS answers to prevent spoofing.
SRI
Subresource Integrity: a hash on a script tag so a modified third-party file is refused.
CWE
Common Weakness Enumeration: MITRE's catalog of software weakness types.
OWASP Top 10
The Open Worldwide Application Security Project's list of the most critical web risks.
WCAG
Web Content Accessibility Guidelines; Level AA is the common legal benchmark.
TTFB
Time to First Byte: delay before the server starts sending the page.
LCP
Largest Contentful Paint: when the main content becomes visible (good ≤ 2.5 s).
CLS
Cumulative Layout Shift: visual stability while loading (good ≤ 0.1).
TBT / INP
Total Blocking Time (lab) and Interaction to Next Paint (field): responsiveness to input.
Canonical URL
The preferred URL for a page when duplicates exist.
Structured data
Machine-readable JSON-LD describing page content for search engines.
Open Graph
Metadata that controls link previews on social and messaging apps.
Lab vs field data
Lab data is a controlled single test; field data is measured from real visitors.

Scan Scope & Tool Coverage Transparency

This automated assessment reviewed 18 public pages. Passive scanning only; no active attacks or credential brute-forcing executed. Point-in-time review does not certify full compliance or replace comprehensive manual penetration testing.

playwright completed

18 pages observed; 0 pages failed; bounded crawl, no authenticated paths or active attacks.

robots.txt completed

Bounded robots inventory observed; sitemap directives sampled.

sitemap.xml completed

1 bounded sitemap document observed; 18 same-origin URLs queued before crawling.

Turnkey Remediation Engineering

Need Help Implementing These Fixes?

Our senior engineering team at R5 Industries provides dedicated remediation sprints to deploy all HTTP response headers, configure Cloudflare zero-trust rules, resolve Core Web Vitals bottlenecks, and inject schema markup for you.

Engineering Retainer Benefits:

  • Performance review and measured improvement plan
  • Zero-trust Cloudflare WAF & CSP deployment
  • Validated Schema.org rich snippets injection
  • Free post-remediation verification re-audit