generated: '2026-09-05' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.3barbiologics.com https: true tls_version: TLSv1.3 cert_expires: Oct 21 15:20:23 2026 GMT hsts: true hsts_max_age: 300 hsts_note: >- 300 seconds is five minutes. The RFC 6797 preload threshold and common practice is 31536000 (one year); a five-minute max-age gives a returning visitor essentially no protection against an SSL-stripping downgrade, because the policy has almost always expired between visits. This is the Pantheon platform default for a site that has not enabled full HSTS. - host: 3barbiologics.com https: false https_error: tls-certificate-name-mismatch hsts: null note: >- The apex domain is broken over HTTPS. It resolves to Pantheon (23.185.0.2) but the certificate presented is CN=pantheonsite.io, whose SANs are *.getpantheon.com, *.gotpantheon.com, *.pantheon.io, *.pantheonsite.io, getpantheon.com, gotpantheon.com and pantheonsite.io — none of which covers 3barbiologics.com. Every browser shows a certificate warning. Plain HTTP to the apex returns 404 rather than redirecting to www, so there is no working path from `3barbiologics.com` to the site by either scheme. A visitor who types the domain without `www.` does not reach 3Bar Biologics. domains: - domain: 3barbiologics.com dnssec: false caa: [] spf: true dmarc: false findings: - id: apex-tls-mismatch severity: high summary: The apex domain serves a certificate that does not cover it, and does not redirect on HTTP. detail: >- https://3barbiologics.com/ fails the TLS handshake with a name mismatch; http://3barbiologics.com/ returns 404 with no Location header. Only https://www.3barbiologics.com/ works. evidence: - {url: 'https://3barbiologics.com/', http_status: 0, error: certificate name mismatch (CN=pantheonsite.io)} - {url: 'http://3barbiologics.com/', http_status: 404, redirect_url: null} - {url: 'https://www.3barbiologics.com/', http_status: 200} remediation_owner: provider - id: preproduction-hostname-leak severity: medium summary: >- The production homepage hard-codes 79 absolute URLs pointing at Pantheon platform hostnames, including the site's only Privacy Policy link. detail: >- www.3barbiologics.com serves HTML containing 26 absolute links to https://dev-3bar-biologics.pantheonsite.io and 53 to https://live-3bar-biologics.pantheonsite.io. The dev host is reachable, returns 200, and serves the same WordPress REST API as production — it is a pre-production environment exposed to the public internet and linked to from the production site. The Privacy Policy link in the page footer points at https://dev-3bar-biologics.pantheonsite.io/privacy-policy/ rather than at the canonical www.3barbiologics.com/privacy-policy/, which does exist and returns 200. Font assets are also loaded cross-origin from the live-* platform host. consequence: >- Visitors following the Privacy Policy link land on an unbranded platform hostname. Search engines and AI crawlers see duplicate content on three hostnames, splitting canonical signal. Anything staged on the dev environment is publicly readable, including through its own REST API. evidence: - {url: 'https://www.3barbiologics.com/', http_status: 200, finding: '26 dev-* and 53 live-* absolute pantheonsite.io URLs in the served HTML'} - {url: 'https://dev-3bar-biologics.pantheonsite.io/privacy-policy/', http_status: 200, finding: 'the target of the production footer Privacy Policy link'} - {url: 'https://dev-3bar-biologics.pantheonsite.io/wp-json/', http_status: 200, finding: 'the pre-production environment serves the same REST API'} - {url: 'https://www.3barbiologics.com/privacy-policy/', http_status: 200, finding: 'the canonical page exists and is not the one linked'} remediation_owner: provider - id: no-dmarc severity: medium summary: SPF is published but DMARC is not. detail: >- An SPF record exists for 3barbiologics.com, but there is no _dmarc TXT record, so there is no policy telling receivers what to do with mail that fails authentication and no reporting channel. The company publishes a sales address (Sales@3BarBiologics.com) on its site, which is the address a spoofing campaign would impersonate. remediation_owner: provider - id: no-dnssec-no-caa severity: low summary: Neither DNSSEC nor CAA is configured for 3barbiologics.com. detail: >- No DNSSEC signing and no CAA record restricting which certificate authorities may issue for the domain. Both are common absences and neither is exploitable on its own. remediation_owner: provider - id: hsts-max-age-300 severity: low summary: HSTS is present on www but expires after five minutes. detail: See the hsts_note on the www host above. remediation_owner: provider