Understanding Results
Finding structure
Each finding represents a single vulnerability:
Severity levels
| Severity | CVSS range | Action |
|---|---|---|
| Critical | 9.0 - 10.0 | Fix immediately - active exploitation likely |
| High | 7.0 - 8.9 | Fix within days - significant risk |
| Medium | 4.0 - 6.9 | Fix within weeks - moderate risk |
| Low | 0.1 - 3.9 | Fix when convenient - minimal risk |
| Info | 0.0 | Informational - no direct security impact |
Each finding includes a CVSS v3.1 vector string (e.g. CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N) that breaks down how the score was calculated. Hover over the vector string in the results page to see a tooltip explaining each metric. Admin users can override the AI-assigned severity if needed.
Tool results
Each tool reports its own status independently:
| Status | Meaning |
|---|---|
pending | Tool has not started yet |
running | Tool is currently executing |
complete | Tool finished and reported results |
failed | Tool encountered an error |
A pentest is complete when all tools have finished (regardless of individual tool status).
Prioritizing fixes
- Start with critical and high findings
- Group findings by type (e.g., fix all XSS at once)
- Use retest commands to verify each fix
- Run a follow-up pentest to confirm the full fix