Sample report

This is the report you'd hand your client

Illustrative example for voryng.com. It reflects the format and level of detail of the report your clients will receive.

Illustrative data · 2026-09-26

Overall security

0/100
Grade: B
Medium risk

Priority this week

Recommended actions

What's happening

Without CSP, the browser has no allowlist of script origins, widening the attack surface for content injection (XSS).

How to fix it

Add the CSP header in report-only mode to identify your site's resources before enabling blocking.

✦AI Insights·Next.js
MEDIO

voryng.com has HTTPS active, TLS 1.3 and HSTS correctly configured. The 3 detected findings are all low to medium impact and can be fixed in a few hours. Resolving them would raise the score from 78 to over 90 and eliminate XSS and content injection vectors.

Protected categories

32/47

Findings

3

0 priority

Detected positive aspects

✓HTTPS enforced with a 301 redirect from HTTP
✓Valid, current TLS certificate (TLS 1.3)
✓HSTS header present with an adequate max-age
✓X-Content-Type-Options: nosniff configured
✓SPF and DMARC records present in DNS

Detected risks

Content-Security-Policy header missing

Medium

Without CSP, the browser has no allowlist of script origins, widening the attack surface for content injection (XSS).

HTTP response without 'Content-Security-Policy' header

Permissions-Policy header absent

Low

Access to browser APIs your site doesn't need (camera, microphone, geolocation) is not restricted.

HTTP response without 'Permissions-Policy' header

Cookie without an explicit SameSite attribute

Low

A cookie without SameSite falls back to browser defaults and may be sent on third-party requests.

Set-Cookie: session=…; Secure (no SameSite)

Positive points

✔ HTTPS enforced with a 301 redirect from HTTP
✔ Valid, current TLS certificate (TLS 1.3)
✔ HSTS header present with an adequate max-age
✔ X-Content-Type-Options: nosniff configured
✔ SPF and DMARC records present in DNS

How to read your report

A report that tells you what to do, not just what's wrong

  • 1

    What was detected

    Each finding explains what we found on your site and why it matters for your business, without jargon.

  • 2

    What to prioritize

    We rank findings by severity (critical, medium, low) so you know what to fix first.

  • 3

    Who should fix it

    We tell you whether it's for your tech team, your hosting provider or your web developer.

  • 4

    How to verify the improvement

    Re-scan after applying the changes and compare the score to confirm the issue is resolved.

Scan a client's site for free

No signup · No card · Results in seconds

Sample website security report for clients | Voryng