Understanding Scan Results
How to read and interpret your scan report.
After a scan completes, Barrion presents a report covering your site's security posture. This page explains each section of the report and how to interpret the data.
Executive Summary
The top of every scan report displays a high-level overview:
- Security score -- A numeric score from 0 to 100, where 100 represents a perfect security configuration.
- Letter grade -- A grade from A through F derived from the score.
- Scan duration -- How long the scan took to complete.
- Trend indicator -- Whether your score is improving, stable, or declining compared to previous scans of the same domain.
The trend indicator requires at least two completed scans for the same domain to appear.
Results by Category
Findings are organized into 10 security categories. Each category groups related checks together so you can focus on specific areas of your security configuration:
- TLS/SSL
- Security Headers
- Content Security Policy (CSP)
- CORS
- Cookie Security
- Email Security
- Network Security
- XSS Protection
- Clickjacking
- Miscellaneous
Each category shows a summary of how many checks passed and failed within it, allowing you to quickly identify weak areas.
Individual Check Details
Expanding any check reveals its full details:
Standard Fields
| Field | Description |
|---|---|
| Name | The security check that was performed |
| Status | Passed, Failed, or Requires Upgrade |
| Severity | Critical, High, Medium, or Low |
| CVSS Score | Numeric score (0.0--10.0) based on CVSS v3.1 |
| Description | Detailed explanation of what the check evaluates |
| Finding | The specific observation on your site |
| Recommendation | Steps to remediate the issue |
Multi-Checks
Some checks are multi-checks -- a parent check that contains multiple child findings. For example, a "Cookie Security" parent check may include separate child findings for the Secure flag, HttpOnly flag, and SameSite attribute. Each child finding has its own status and severity while contributing to the parent check's overall result.
Multi-checks let Barrion report granular findings without overwhelming the category-level summary.
Severity Levels
Barrion assigns one of four severity levels to each finding, based on CVSS v3.1 scoring:
| Severity | CVSS Range | Impact |
|---|---|---|
| Critical | 9.0 -- 10.0 | Immediate risk. Exploitation requires minimal effort and can lead to full compromise. Fix these first. |
| High | 7.0 -- 8.9 | Significant risk. Likely exploitable with moderate effort. Prioritize remediation. |
| Medium | 4.0 -- 6.9 | Moderate risk. May require specific conditions to exploit. Address in your next maintenance window. |
| Low | 0.0 -- 3.9 | Minimal risk. Informational or best-practice recommendations. Address when convenient. |
Affected URLs
For checks that evaluate individual pages rather than domain-wide settings, the report includes a list of affected URLs. This tells you exactly which pages on your site triggered the finding.
For example, a mixed-content check might report that https://example.com/blog loads an image over HTTP while https://example.com/about does not. The affected URLs list makes it clear where the issue exists.
The number of affected URLs depends on your plan's crawl depth. Higher-tier plans crawl more pages, potentially uncovering issues on routes that lower-tier scans would not reach.
Score History and Trends
If you have run multiple scans for the same domain, Barrion tracks your score over time. The trend indicator on the executive summary reflects the direction of change:
- Improving -- Your latest score is higher than the previous scan.
- Stable -- Your score has not changed significantly.
- Declining -- Your latest score is lower than the previous scan.
Use score history to validate that security fixes are having the intended effect and to detect regressions introduced by new deployments.