The security scan of rapidvuln.com found 6 medium and low severity issues. No critical vulnerabilities were detected, but 2 issues should be addressed this week to harden your security posture. Detailed fix instructions are included for each finding.
DKIM key for selector 'resend' appears to be approximately 1024 bits โ 1024-bit RSA keys are considered weak by modern standards and NIST has deprecated them. A well-resourced attacker could factor this key, breaking your email authentication.
A forged DKIM signature lets an attacker send phishing or fraud emails that cryptographically appear to come from your domain โ bypassing email filters that rely on DKIM as a trust signal, and making impersonation emails indistinguishable from your real ones.
Example: A security researcher demonstrated in a published study that 512-bit DKIM keys could be factored in under 72 hours using cloud computing resources costing less than $100 โ allowing anyone with that capability to forge valid email signatures for the affected domain.
Upgrade the DKIM key for selector 'resend' to 2048 bits. Generate a new key through your email provider, update the DNS TXT record to the new public key, and retire the old 1024-bit key.
CSP script-src allows 'unsafe-inline' โ an injected or hijacked script can still run freely
This setting defeats most of the protection CSP is meant to provide. If a third-party script you rely on is ever compromised โ the exact mechanism behind most 'watering hole' attacks โ it will execute without restriction and with no warning.
Example: A vendor's analytics or chat-widget script gets compromised at the source; because the policy still allows it (or allows inline/eval scripts generally), the malicious code runs exactly as if it belonged on the site, with no warning to anyone.
Tighten script-src to an explicit allowlist of trusted domains and drop 'unsafe-inline'/'unsafe-eval'/wildcards. Move inline scripts to external files or use a nonce/hash. Test changes with https://csp-evaluator.withgoogle.com before deploying.
CWE-693 โ Protection Mechanism Failure
A security safeguard that should be protecting the system is missing, disabled, or not strong enough.
/login/ returned HTTP 200 with no authentication challenge. This confirms a login or admin entry point exists at this path.
/login/ returned HTTP 200 with no authentication challenge. This confirms a login or admin entry point exists at this path.
Confirm this login is protected by a strong password and, ideally, multi-factor authentication. Consider IP-restricting it if it's only used by internal staff.
/dashboard/ returned HTTP 200 with no authentication challenge. This confirms a login or admin entry point exists at this path.
/dashboard/ returned HTTP 200 with no authentication challenge. This confirms a login or admin entry point exists at this path.
Confirm this login is protected by a strong password and, ideally, multi-factor authentication. Consider IP-restricting it if it's only used by internal staff.
/robots.txt is present and was used to seed additional path checks.
/robots.txt is present and was used to seed additional path checks.
No action needed โ robots.txt is meant to be public.
/sitemap.xml is present and was used to seed additional path checks.
/sitemap.xml is present and was used to seed additional path checks.
No action needed โ sitemap.xml is meant to be public.
No high-risk open ports were detected from the internet โ your firewall appears to be blocking dangerous services.