Review publicly visible
configuration risks.

Analyze TLS, HTTP headers, cookies, mixed content and selected exposure signals. Insight groups issues, shows measurement scope and where to start. It does not replace a pentest or code audit.

Illustrative product view
76
Technical configuration score: 76/100
TLS
OK No issue detected
Headers
4 missing
XSS
Not detected in scope
Insight organizes visible security signals — before you decide where deeper analysis is needed.

Every issue has a source, scope, confidence level and recommended next step. Results help build a backlog, but they do not replace a pentest.

From scan to a fix list.

Four steps from URL to decision — without guessing whether the issue is TLS, headers, cookies or third-party resources.

HTTPS Scan

Certificate, TLS version and redirect to encrypted connection.

TLSCertRedirect
Headers

CSP, HSTS, X-Frame-Options and other browser protection rules.

CSPHSTSXFO
Cookies

Secure, HttpOnly and SameSite flags on detected cookies.

SecureHttpOnlySameSite

URL analysis

You test a specific URL — homepage, login panel or form. You see scan context and configuration signals detected automatically.

Scan areas · HTTPS
Connection OK
OK
Headers 4
Missing
Cookies 2
Issues
Scan · HTTPS + headers

Problem explanation

Each finding has context: which header, certificate or cookie and why it may increase risk — plus whether it needs human review.

Security priorities
9

Fix priorities

Issues are ordered by potential impact, exposure and detection confidence — not by score alone.

76
+8
68 before
76 after

Same scope · confirm the specific signal

Confirm the fix

Re-run the scan and check whether configuration actually changed in the same scope — not only whether the score went up.

What the module covers

  • TLS & certificate
  • HTTP headers
  • Cookies & CORS
  • Mixed content
  • Code & dependencies
  • Exposure
  • OWASP
  • Standards

Scope depends on scan type and available data. Insight does not issue compliance certification.

Remediation plan

Three actions with the highest technical priority.

Start with issues that have the highest potential impact, scope and detection confidence — not mechanical score chasing. Each item shows the risk, priority rationale and whether a human should verify.

  • Priority by impact · exposure · confidence
  • Risk and scope on every item
  • Score as a supporting indicator
Remediation plan Technical priority · not score gaming
1
Remove the HTTP asset on an HTTPS page Mixed content · high exposure · high confidence
Exposure P1
2
Deploy a Content-Security-Policy Missing policy · needs human review
Headers P1
3
Add Secure/SameSite to 3 cookies 3 cookies · response flags · medium effort
Cookies P2

Score breakdown

What the technical configuration score is made of.

TLS, HTTP headers, cookies and exposure — each component has its own score, measurement status and weight. You see the certificate is fine while headers drag the total down — instead of guessing from one number.

  • Components with weight and measurement status
  • A separate 0–100 score per area
  • Clear view of what drags the score down
Configuration score components — weight · status · issues.
SSL / TLS High weight · checked · 0 issues
92/100
HTTP headers High weight · checked · 4 missing
58/100
Cookies Medium weight · checked · 3 to fix
64/100
Exposure · XSS / SRI Medium weight · XSS signals: not detected
71/100

Security modules

Areas ordered by priority.

The “start here” group sits on top — by impact and exposure, not lowest score alone. Every area opens into a full report with findings and recommendations.

  • Priority before the numeric score alone
  • 0–100 score as orientation
  • Drill-down into each area report
START HERE
HTTP headers High impact · 4 missing
58/100 Open
Cookies 3 cookies · Secure/SameSite flags
64/100 Open
Subresource Integrity Script exposure · medium confidence
66/100 Open
STABLE
SSL / TLS No issue detected in scope
92/100 Open
JavaScript exposure XSS signals: not detected
85/100 Open

Scan health

You know what was measured — and what the scan did not cover.

Every check shows status, method and limits. ZAP appears only when it was run. “Not detected” does not mean “no vulnerability”.

  • Status: checked · issue · not detected · not measured
  • Method and scan date with scope
  • Honest limits: automated scan, not a pentest
Scan: Jul 22, 2026 · scope: public URL · no authentication
TLS certificate Network connection
Checked
HSTS Response header
Issue
CSP Response header
No policy
Cookies Response flags
3 issues
XSS signals Static analysis
Not detected
ZAP Extended scan
Not run
“Not detected” ≠ no vulnerability · ZAP only when started
For agencies and freelancers

Built for configuration scans across clients

  • Keep each scan’s scope and date
  • Compare results before and after shipping
  • Export issues and evidence to the client report
  • Refresh the module without a full re-audit

Find the first
risky configuration.

Check a public URL, see the control scope and start with a concrete technical change.

No credit card Report with date and sources No account required