Report Preview

CMS reports built for triage, ownership, and remediation

Audit My CMS turns passive public signals into structured report sections with severity rationale, observed evidence, limitations, and practical remediation guidance.

Summary

Owner-friendly overview

Shows the target, scan scope, scanner execution completeness, severity distribution, high-level priorities, positive checks, and areas that need manual review.

Useful for client conversations and maintenance reviews.
Evidence

Technical details without the noise

Groups vulnerability applicability, exposure findings, infrastructure signals, external attack surface evidence, SEO/privacy signals, third-party inventory, and accessibility issues with affected URLs, matched text, and observed public evidence.

Useful for developers and technical account managers.
Action

Remediation-focused next steps

Turns findings into recommended fixes, owner-friendly priorities, implementation examples, closure criteria, retest guidance, and risk-acceptance notes for follow-up work.

Useful for turning scan results into a work plan.

Typical report sections

  • Executive summary, priority actions, and severity overview
  • Scanner execution completeness, limitations, and checks populated
  • CMS core, extension, module, plugin, and theme inventory
  • Version-matched vulnerability records and manual-review records
  • Patched or not-applicable vulnerability records ruled out
  • Public sensitive file, API, cache, CORS, and site exposure checks
  • Infrastructure, TLS, header, IP, ASN, and CDN/cache observations
  • External attack surface assets with DNS, HTTP, TLS, and review-signal evidence
  • Email and DNS security posture
  • SEO, privacy, form, reputation, and third-party inventory
  • SRI coverage for applicable external JavaScript assets
  • Homepage accessibility findings, remediation notes, retest guidance, and report appendices

PDF and DOCX outputs

  • PDF focuses on clean delivery: executive summary, technical findings, evidence, remediation, scope, and limitations.
  • DOCX includes the same core findings plus editable working appendices for ownership, retest, risk acceptance, remediation tracking, and sign-off.
  • Both outputs keep known third-party services visible as inventory while avoiding noisy unknown-domain findings for classified services.
  • Both outputs separate passive findings from version-matched vulnerability records so owners can triage public evidence without treating it as proof of exploitation.