- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ Target IP:          167.179.167.166
+ Target Hostname:    passbolt.lan.ddnsgeek.com
+ Target Port:        443
---------------------------------------------------------------------------
+ SSL Info:           Subject:  /CN=passbolt.lan.ddnsgeek.com
                      CN:       passbolt.lan.ddnsgeek.com
                      SAN:      passbolt.lan.ddnsgeek.com
                      Ciphers:  TLS_AES_128_GCM_SHA256
                      Issuer:   /C=US/O=Let's Encrypt/CN=R13
+ Platform:           Unknown
+ Start Time:         2026-04-05 08:41:00 (GMT0)
---------------------------------------------------------------------------
+ Server: nginx
+ [999961] /: Cookie passbolt_session created without the secure flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-login-url' found, with contents: /auth/login.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-version' found, with contents: 1.3.0.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-debug' found, with contents: There is no user associated with this key. No key id set..
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-progress' found, with contents: stage0.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-error' found, with contents: true.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-pubkey-url' found, with contents: /auth/verify.json.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-logout-url' found, with contents: /auth/logout.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-verify-url' found, with contents: /auth/verify.
+ [999100] /auth/login?redirect=%2F: Uncommon header(s) 'x-gpgauth-authenticated' found, with contents: false.
+ [999961] /auth/login?redirect=%2F: Cookie csrfToken created without the secure flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ [95] /auth/login?redirect=%2F: Cookie csrfToken created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
