Shopify Storefront Check
vulnerable.lab.netclick.tech
Results Summary
29 findings detected across vulnerable.lab.netclick.tech.
Severity Breakdown
Total findings detected across all components. The public summary below groups findings by vulnerability type. To see every affected component in full detail, run a free scan on your own domain at vulnify.app/tools.
Findings Overview
29 unique issues shown below, grouped from 29 total findings. When a vulnerability affects multiple components, it is listed once with the affected component count.
-
critical Potentially sensitive paths are accessible
/m/vulnerable/admin (200, admin-surface, confidence:medium), /m/vulnerable/wp-admin (200, admin-surface, confidence:medium), /m/vulnerable/.git/HEAD (200, reachable-artifact, confidence:high), /m/vulnerable/.env (200, sensitive-artifact, confidence:h…
-
high Strict-Transport-Security (HSTS): missing
Ensures the browser only connects over HTTPS
-
high Content-Security-Policy (CSP): missing
Prevents XSS and data injection attacks
-
high Content-Security-Policy header missing
No CSP header detected. XSS impact surface is larger.
-
high Cookie missing Secure flag
sessionid: sessionid=lab-vulnerable
-
high HTTP resources detected on page
Found 2 HTTP resource reference(s). Active=1, passive=1.
-
high Potentially outdated JavaScript libraries were identified
jQuery 1.12.4 (recommended >= 3.5.0)
-
medium X-Frame-Options: missing
Prevents clickjacking attacks
-
medium X-Content-Type-Options: missing
Prevents MIME-type sniffing
-
medium X-XSS-Protection: missing
Legacy XSS protection (modern browsers use CSP)
-
medium Referrer-Policy: missing
Controls how much referrer information is shared
-
medium Permissions-Policy: missing
Controls browser features and APIs
-
medium [REDACTED]: missing
Restricts Adobe Flash and PDF policies
-
medium Cookie missing HttpOnly flag
sessionid: sessionid=lab-vulnerable
-
medium Cookie missing SameSite attribute
sessionid: sessionid=lab-vulnerable
-
medium CORS wildcard origin detected
Access-Control-Allow-Origin: *
-
medium Different start URLs resolve to different final destinations
https://vulnerable.lab.netclick.tech/m/vulnerable/ | http://vulnerable.lab.netclick.tech/m/vulnerable/
-
medium Disclosure headers or generator metadata expose stack details
Server: nginx/1.24.0 (Ubuntu), X-Powered-By: PHP/7.4.3
-
medium Administrative entry surfaces responded publicly
/m/vulnerable/admin (200), /m/vulnerable/wp-admin (200)
-
medium Library exposure was confirmed across multiple sampled routes
jQuery on /m/vulnerable/, /m/vulnerable/?path=readme&url=https://example.com&cmd=status, /m/vulnerable/?q=catalog, /m/vulnerable/?id=1, /m/vulnerable/?cmd=status
9 findings are grouped in this public summary
This public page groups findings by vulnerability type to avoid exposing sensitive configuration details about vulnerable.lab.netclick.tech. To see the full breakdown including every affected component, version number, and remediation step, run a free scan on your own domain using Vulnify.
Run a Free Scan on vulnerable.lab.netclick.techWhat the Shopify Storefront Check Covers
This security profile for vulnerable.lab.netclick.tech was generated by Vulnify. The check analyzes:
- Storefront theme and app detection
- JavaScript and asset security review
- Security headers and CSP assessment
- Third-party script and integration checks
Prioritized Actions
- highAdd Content-Security-Policy (CSP) header
- highAdd Strict-Transport-Security (HSTS) header
- highAdd baseline CSP
- highHarden cookies
- highUse explicit origins
- highMigrate asset links to HTTPS
- highPrioritize active mixed content
- highRestrict sensitive paths
- highAdd edge-layer deny rules
- highUpgrade jQuery
- mediumValidate storefront target
- mediumAdd X-Frame-Options header
- mediumAdd X-Content-Type-Options header
- mediumAdd Referrer-Policy header
- mediumUse hardened cookie prefixes where possible
Run a Full Security Scan on vulnerable.lab.netclick.tech
Check for XSS, SQL injection, CSRF, broken authentication, and 50+ additional security tests with a complete vulnerability assessment.
About This Check
This report was generated using Vulnify's free security tools. Results reflect the configuration at the time of the check. For ongoing monitoring, detailed remediation guidance, and vulnerability scanning across 50+ security tests, create a free Vulnify account.
Last checked:
Report abuse
If this page contains sensitive data, copyright issues, or should not be public, report it.