DreamShop · Automated Security Audit
Certificate of Security Audit
This certifies that the production storefront https://dreamshop.com.ng was audited on October 6, 2026 and re-audited on October 7, 2026 following a full security remediation cycle — passing all checks with zero exploitable findings and zero secrets in repository history.
- Verdict
- PASS
- Issued
- October 7, 2026
- Certificate ID
- DS-SEC-2026-1007
Vulnerability scan
Nuclei 3.11 (ProjectDiscovery)
- Templates executed
- 6,478
- Requests sent
- ~10,000
- Findings
- 0
Full template set, low through critical severity. Denial-of-service and intrusive templates excluded to protect shoppers.
TLS / encryption audit
testssl.sh 3.2
- Checks completed
- 662
- Protocols enabled
- TLS 1.2 · 1.3
- Weak protocols
- None
SSLv2, SSLv3, TLS 1.0 and TLS 1.1 are disabled. Certificate: valid Let’s Encrypt for dreamshop.com.ng.
HTTP security headers
Response inspection
- HSTS
- Enforced
- Content-Security-Policy
- Enforced
- Frame protection
- Enforced
Strict-Transport-Security, CSP, X-Frame-Options, nosniff, Referrer-Policy and Permissions-Policy on every response.
Edge attack mitigation
Vercel Attack Challenge Mode
- Bot mitigation
- Active
- Sensitive paths
- Blocked
- Trace methods
- Disabled
The scanner itself was rate-limited and challenged at the edge. /.env, /.git, /server.js and debug paths all return blocked.
Known exploit resistance
Tested explicitly and confirmed not vulnerable:
- Heartbleed
- CCS Injection
- Ticketbleed
- BREACH
- SWEET32
- FREAK
- DROWN
- LOGJAM
- LUCKY13
- Winshock
- RC4 Bias
Methodology & scope
Point-in-time automated audit first performed on October 6, 2026 against the live production domain over HTTPS, using Nuclei with the complete ProjectDiscovery template library and testssl.sh for the transport-layer assessment. Denial-of-service and intrusive templates were excluded so no shopper traffic was affected. The October 7 re-audit repeated the transport, header, dependency, accessibility, performance and crawl-surface checks after a full security remediation cycle (credential rotation and git history rewrite), and added a full-history secrets scan and the e-commerce functional checklist. This certificate reflects the security posture observed on the re-audit date; DreamShop re-audits after every major release. Report archives: nuclei-report.txt, testssl-report.txt (CSV/HTML) and gitleaks-report.json.