html Sample report , musterwerke.de | itsecurity.today
Report no. ITS-2026-04812
⚠️ Demonstration report , this company, this domain and all values are fictitious and are for illustrative purposes only.

IT security report

musterwerke.de · Musterwerke GmbH, Musterstadt · Scan dated 27.09.2026, 14:32 · itsecurity.today black-box analysis v1
Security score 58/100
2 urgent2 medium2 info9 OK

Summary

#FindingSeverityRemediation effort
1Debug log publicly accessible (612 MB)🔴 urgent5 minutes
2Plugin with known vulnerability (CVE-2026-08151*)🔴 urgent10 minutes
3Editorial team enumerable via API (3 names)🟠 medium15 minutes
4XML-RPC enabled, no login lockout🟠 medium10 minutes
5DMARC not enforced (p=none)⚪ info15 minutes
6Security headers missing⚪ info5 minutes

Overall impression: A fundamentally solid TLS configuration and an up-to-date CMS version. You should close two findings this week: they fall into the category of “an attacker can find this with two clicks from outside”. Both can be remediated in under 15 minutes.

🔴 Detailed results , urgent

urgent · Finding 1 of 6

Debug log publicly accessible , 612 MB of server internals

Your error log is publicly available on the web. Anyone , even without logging in , can download it. It contains complete file paths on your server, PHP error messages with line numbers and parts of the internal plugin structure. On shared hosting, this is the map for the next step of an attack. In addition: with 612 MB of pull volume per request, you risk your transfer volume quotas.

GET https://musterwerke.de/wp-content/debug.log → HTTP 200 · Content-Type: text/plain · 641.722.211 Bytes Erste Zeile: [12-Feb-2026 09:14:02 UTC] PHP Warning: mysqli_query(): … in /hp/xy/12/ab/www/musterwerk/wp-includes/…
Remediation (5 minutes): Delete the log file in your hosting provider's file manager, then in the wp-config.php replace the following:
define('WP_DEBUG', false);
define('WP_DEBUG_DISPLAY', false);
define('WP_DEBUG_LOG', false);
⏱ Effort: approx. 5 minutes · We will verify the fix for you free of charge.
urgent · Finding 2 of 6

Installed plugin with a registered vulnerability

The plugin “Newsletter Pro” in version 9.3.3 has a publicly documented vulnerability (CVSS 7.1): When newsletter forms are displayed, scripts can be injected and executed without authentication. Your installed version can be clearly identified from the public version file.

GET https://musterwerke.de/wp-content/plugins/newsletter-pro/readme.txt → HTTP 200 · "Stable tag: 9.3.3" Known vulnerability affects versions ≤ 9.3.3 · fixed in 9.3.4+
Remediation (10 minutes): In your CMS, update “Newsletter Pro” to the current version under Extensions. First briefly read the note, as it involves adjustments to the form layout.
⏱ Effort: approx. 10 minutes including a brief visual check

🟠 Detailed results , medium

medium · Finding 3 of 6

Editorial team enumerable via the API

The interface of your CMS outputs all user accounts with slug and display name. Attackers use exactly this list as a target register for targeted phishing e-mails and password-spray attacks.

GET https://musterwerke.de/wp-json/wp/v2/users → HTTP 200 [{"slug":"m.weber","name":"Maria Weber"},{"slug":"j.fuchs","name":"Jonas Fuchs"},{"slug":"redaktion","name":"Musterwerke Redaktion"}]
Remediation: Disable user enumeration via a Must-Use plugin , your author archive pages will remain intact. The snippet is included in the fix package.
medium · Finding 4 of 6

XML-RPC enabled + login page without lockout

XML-RPC is enabled with “multicall”: this allows hundreds of login attempts to be bundled into a single request. As your login page also does not display a failure limit, there is currently no effective login throttling.

POST https://musterwerke.de/xmlrpc.php (system.listMethods) → HTTP 405 for GET (active) · Method list includes: system.multicall, pingback.ping 5 repeated test requests: no blocking, no delay
Remediation: Block XML-RPC if you do not need pingbacks, a rule in the .htaccess:
<Files "xmlrpc.php">
  Require all denied
</Files>
⏱ Effort: 10 minutes

⚪ Detailed results , info

info · Finding 5 of 6

DMARC set to “p=none” , monitoring rather than blocking

SPF and DKIM are present and correct. However, the DMARC policy is set to “none” , spoofed emails in your company name would not be blocked as forgeries by the recipient. Recommendation: after a monitoring phase, change to p=quarantine instead.

info · Finding 6 of 6

Security headers missing

X-Content-Type-Options, X-Frame-Options and Referrer-Policy are missing. Individually minor, together they significantly hinder click-based attacks and MIME confusion. Four lines in the .htaccess file are sufficient.

✅ Checked and OK

TLS 1.3 with a strong cipher suite · TLS 1.0/1.1 rejected · Certificate valid until 18.02.2027 (automatic renewal detected) · HSTS active · Clean HTTP-to-HTTPS redirect · No backup traces (26 standard paths checked) · No directory listings · uploads/includes protected · CMS core up to date · SPF+DKIM present · 9 of 15 test groups passed without findings.

This is what your report looks like

Run a real scan: the basic result is free. You receive the detailed report with all fix snippets for 99 €. You only pay if we actually find something.

Start free scan

This demo report uses fictional data only. This page does not set cookies and does not load third-party scripts.