logotypelogotype
logotype

Security scan results

Uncover hidden risks! Upgrade for deeper analysis and fortify your site's defenses against potential threats.
For upgrade click here

Scan completed. 4 issues found.
Low1
Medium3
High0
Critical0
  • Domain: primus-design.com
  • Status: Completed
  • Scanned at: Jul 17 2026 23:22

Assets

Domains and Subdomains
ftp.primus-design.com
mail.primus-design.com
IPs
219.94.128.179
Technology Stack
HTML5
HTTPServer[nginx]
MetaGenerator[WordPress 7.0.1]
nginx
Open-Graph-Protocol
Script[application/json,module,speculationrules]
Wordpress-Contact-Form
WordPress

Security Issues

Email Security
Low (0)
Medium (2)
High (0)
Critical (0)
DKIM not enabled
Medium
Description

"DKIM Not Enabled" refers to the absence or misconfiguration of DKIM (DomainKeys Identified Mail) for a domain. DKIM is an email authentication method that allows the sender to digitally sign outgoing emails, providing a means to verify the integrity and authenticity of the messages. When DKIM is not enabled, it means that the domain's email infrastructure is not utilizing DKIM, leaving the domain susceptible to email forgery and potential email-based attacks.

Recommendation

Enable DKIM for Your Domain: Implement DKIM for your domain by generating and publishing DKIM keys. Consult your email service provider or system administrator for specific instructions on configuring DKIM correctly. DKIM keys are cryptographic signatures that are added to outgoing emails to verify their authenticity. Generate and Publish DKIM Records: Generate DKIM keys and publish the corresponding DKIM records in your domain's DNS. The DKIM records contain the public key information that receiving email servers use to validate the DKIM signatures on your outgoing emails. Monitor DKIM Signatures: Regularly monitor the DKIM signatures on your outgoing emails to ensure they are properly added and validated by receiving email servers. Implement mechanisms to track and analyze DKIM signature failures, which may indicate configuration issues or potential tampering attempts. Regularly Review and Update DKIM Configuration: Periodically review your DKIM configuration to ensure it remains accurate and up to date. Update DKIM keys and records as necessary, especially when rotating keys or making changes to your email infrastructure.

Proofs

Unable to find DKIM record for primus-design.com

Compliance Issues
ISO-27001:2013 A.14.1.3
ISO-27001:2013 A.14.1.2
ISO-27001:2013 A.13.2.1
ISO-27001:2013 A.13.1.3
ISO-27001:2013 A.13.1.1
NIST SP 800-53 Rev. 4 SC-7
NIST SP 800-53 Rev. 4 AC-10
NIST SP 800-53 Rev. 4 AC-4
HIPAA Security Rule 45 C.F.R. § 164.312(e)
HIPAA Security Rule 45 C.F.R. § 164.312(c)
HIPAA Security Rule 45 C.F.R. § 164.312(b)
HIPAA Security Rule 45 C.F.R. § 164.312(a)(1)
HIPAA Security Rule 45 C.F.R. § 164.310(b)
HIPAA Security Rule 45 C.F.R. § 164.310(a)(1)
HIPAA Security Rule 45 C.F.R. § 164.308(a)(4)(ii)(B)
DMARC not enabled
Medium
Description

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that helps prevent email spoofing and phishing attacks. When DMARC is not enabled, it means that the domain owner has not implemented the necessary DNS records to enforce DMARC policies. This misconfiguration leaves the domain vulnerable to email impersonation and increases the likelihood of successful phishing attacks targeting users associated with the domain.

Recommendation

Enable DMARC: Implement DMARC for your domain by creating and publishing DMARC DNS records. Set DMARC Policies: Define appropriate DMARC policies based on your organization's requirements. DMARC policies include "none," "quarantine," and "reject." Start with a "none" policy to monitor email authentication results without taking any action.

Proofs

Unable to find DMARC record for primus-design.com

Compliance Issues
ISO-27001:2013 A.14.1.3
ISO-27001:2013 A.14.1.2
ISO-27001:2013 A.13.2.1
ISO-27001:2013 A.13.1.3
ISO-27001:2013 A.13.1.1
NIST SP 800-53 Rev. 4 SC-7
NIST SP 800-53 Rev. 4 AC-10
NIST SP 800-53 Rev. 4 AC-4
HIPAA Security Rule 45 C.F.R. § 164.312(e)
HIPAA Security Rule 45 C.F.R. § 164.312(c)
HIPAA Security Rule 45 C.F.R. § 164.312(b)
HIPAA Security Rule 45 C.F.R. § 164.312(a)(1)
HIPAA Security Rule 45 C.F.R. § 164.310(b)
HIPAA Security Rule 45 C.F.R. § 164.310(a)(1)
HIPAA Security Rule 45 C.F.R. § 164.308(a)(4)(ii)(B)
Security Headers
Low (0)
Medium (1)
High (0)
Critical (0)
Missing Security Headers
Medium
Description

Security headers need to be implemented. Check the "Proofs" section for detailed information on which headers are missing.

Recommendation

Implement the headers.

Proofs
  • Cache-Control
  • Clear-Site-Data
  • Cross-Origin-Embedder-Policy
  • Cross-Origin-Opener-Policy
Compliance Issues
ISO-27001:2013 A.14.1.3
ISO-27001:2013 A.14.1.2
ISO-27001:2013 A.13.2.3
ISO-27001:2013 A.13.2.1
ISO-27001:2013 A.13.1.1
ISO-27001:2013 A.8.2.3
NIST SP 800-53 Rev. 4 SC-12
NIST SP 800-53 Rev. 4 SC-11
NIST SP 800-53 Rev. 4 SC-8
HIPAA Security Rule 45 C.F.R. § 164.314(b)(2)(i)
HIPAA Security Rule 45 C.F.R. § 164.312(e)(2)(ii)
HIPAA Security Rule 45 C.F.R. § 164.312(e)(2)(i)
HIPAA Security Rule 45 C.F.R. § 164.312(e)(1)
HIPAA Security Rule 45 C.F.R. § 164.308(b)(2)
HIPAA Security Rule 45 C.F.R. § 164.308(b)(1)
ISO-27001:2013 A.14.2.4
ISO-27001:2013 A.12.5.1
ISO-27001:2013 A.12.2.1
NIST SP 800-53 Rev. 4 SI-7
NIST SP 800-53 Rev. 4 SC-16
HIPAA Security Rule 45 C.F.R. § 164.312(c)(2)
HIPAA Security Rule 45 C.F.R. § 164.312(c)(1)
HIPAA Security Rule 45 C.F.R. § 164.312(b)
HIPAA Security Rule 45 C.F.R. § 164.308(a)(1)(ii)(D)
Certificates
Low (0)
Medium (0)
High (0)
Critical (0)
No issue found
Open Ports
Low (1)
Medium (0)
High (0)
Critical (0)
Exposed Port
Low
Description

The security issue of "Exposed Ports" refers to network ports on a system or device that are accessible and visible to external networks or unauthorized entities. Exposed ports can pose significant security risks as they provide potential entry points for attackers to gain unauthorized access, launch attacks, or exploit vulnerabilities in services or applications running on those ports.

Recommendation

Conduct Port Scans and Audits: Regularly perform port scans and audits to identify any open and exposed ports on your systems or devices. Use network scanning tools to identify which ports are open and accessible from external networks. Close Unnecessary Ports: Close or disable any unnecessary ports that are not actively used or required for legitimate business purposes. Limiting the number of open ports reduces the attack surface and minimizes the potential entry points for unauthorized access. Implement Network Firewalls: Utilize network firewalls to control and filter incoming and outgoing traffic. Configure the firewalls to block access to unnecessary ports and only allow traffic through authorized and required ports based on predefined rules and policies.

Proofs
addressportserviceprotocol
219.94.128.17925smtptcp
219.94.128.17922sshtcp
219.94.128.17921ftp?tcp
219.94.128.17980http?tcp
Compliance Issues
ISO-27001:2013 A.9.1.2
NIST SP 800-53 Rev. 4 CM-7
NIST SP 800-53 Rev. 4 AC-3
HIPAA Security Rule 45 C.F.R. § 164.312(a)(2)(iv)
HIPAA Security Rule 45 C.F.R. § 164.312(a)(2)(ii)
HIPAA Security Rule 45 C.F.R. § 164.312(a)(2)(i)
HIPAA Security Rule 45 C.F.R. § 164.312(a)(1)
HIPAA Security Rule 45 C.F.R. § 164.310(c)
HIPAA Security Rule 45 C.F.R. § 164.310(b)
HIPAA Security Rule 45 C.F.R. § 164.310(a)(2)(iii)
HIPAA Security Rule 45 C.F.R. § 164.308(a)(4)
HIPAA Security Rule 45 C.F.R. § 164.308(a)(3)
Technologies
Low (0)
Medium (0)
High (0)
Critical (0)
No issue found
Directory Listing
Low (0)
Medium (0)
High (0)
Critical (0)
No issue found
Vulnerabilities
Low (0)
Medium (0)
High (0)
Critical (0)
No issue found