For the complete documentation index, see llms.txt. This page is also available as Markdown.

Statistics

The Statistics page provides a high-level overview of vulnerabilities and findings for a given assessment scope. It can be viewed per assessment or per root entity (Domain, Subnet, Repository, or APK file) to help prioritize remediation efforts.

  • Views – Separate dashboards are available for External Assessments, Internal Assessments, and Code Assessments, each tailored to the nature of the test.

  • Metrics shown:

    • Total vulnerabilities and severity breakdown

    • Percentages of vulnerabilities by severity. External assessments follow the active severity display mode: CVSS uses Critical, High, Medium, Low, or Informational, while VRT uses Bugcrowd-style P1-P5 priorities when VRT data is available.

    • Most common CWE IDs and vulnerability types

    • Top vulnerabilities by CVSS score

    • Vulnerabilities grouped by affected asset or relation

    • Time-based trends of vulnerability discovery

    • For internal assessments: discovered subnets, hosts, services, ports/protocols, and secrets found

    • For code assessments: repository findings, code issue categories, dependency risk, leaked secrets, and inventory coverage

Set the external severity mode from Settings -> External -> Severity Display.

Choose CVSS for standards-aligned risk and compliance views. Choose VRT for bug bounty style prioritization using Bugcrowd's web and API taxonomy. See Bugcrowd VRT.

This page acts as the central reporting view for assessment results, helping security teams understand exposure, identify recurring weaknesses, and track progress over time.

Last updated