notra·
Free scorecard. Sign in required — every finding comes with proof.
D
posture

harborlanterngoods.com

21 passive checks in 74 seconds. Passive only — nothing is probed, nothing touched your checkout. The serious findings need an ownership-verified scan.

6 pass 10 warnings 5 failing

Transport / TLS

Valid TLS certificate
Let's Encrypt · expires in 61 days
TLS 1.0 / 1.1 still offered
Deprecated by RFC 8996
3DES cipher negotiable
SWEET32 (CVE-2016-2183)
HSTS not set
No Strict-Transport-Security header
HTTPS redirect enforced
http → https

Security headers

No Content-Security-Policy
Zero in-browser XSS containment
X-Frame-Options missing
Checkout page is framable
nosniff missing
X-Content-Type-Options not set
Referrer-Policy missing
Permissions-Policy missing
X-Powered-By exposed
PHP/7.4.29, end-of-life

Cookies

Secure flag missing
woocommerce_cart_hash
SameSite not set
session cookie
HttpOnly set
wp_woocommerce_session_*

Email authentication

SPF record present
v=spf1 include:mailgun.org
DMARC not enforced
p=none, report-only
No DKIM selector found
MTA-STS not configured

Exposure surface

Backup file exposed
/wp-content/uploads/.env.bak → 200
Debug log readable
/wp-content/debug.log → 200
.git not exposed
404
Directory listing off
robots.txt present
12 disallow rules
Detected stack
WordPress 6.5.0WooCommerce 8.7.0Bricks 1.9.5WP File Manager 6.0PHP 7.4.29 · EOLnginx 1.18
Verified deep findings
12 verified deep findings, locked2 crit · 2 high · 5 med · 2 low · 1 info
criticalUnauthenticated remote code execution: WP File Manager 6.0 (CVE-2020-25213)
criticalUnauthenticated remote code execution: Bricks theme 1.9.5 (CVE-2024-25600)
highBackup file leaks live Stripe, SMTP and database credentials
highCORS reflects any origin with credentials enabled on the Store API
mediumReflected XSS in product filter 'sort_by' parameter
mediumOpen redirect via unvalidated 'redirect_to' parameter
mediumDeprecated TLS 1.0/1.1 and 3DES (SWEET32) still offered
mediumMissing security headers (CSP, HSTS, X-Frame-Options, nosniff) on a commerce site
mediumAuthenticated stored XSS in WordPress core 6.5.0 (CVE-2024-4439)
lowProduction debug log exposed with server paths and internal errors
lowWooCommerce cart/session cookies missing Secure and SameSite
infoUsernames and software versions enumerable by anonymous visitors
A passive scan can’t safely prove these. Verify the domain is yours and we’ll run the deep audit, evidence and all.
Create free account to unlock

Passive means read-only. The deep audit runs once you prove the domain is yours.

What a full scan adds

Authorize ownership and the deep audit ships verified findings — each with the evidence the scorecard can only hint at.

These rows come from the same checks behind the live scan demo, delivered as a verified report. Unlock them for your domain with a free account.

Your grade in under a minute. Free.

Sign in, run the passive checks, and see your grade in about a minute. Nothing is touched, nothing is probed — the verified deep audit goes deeper whenever you're ready.

Run your free scorecard See a sample report