CallBegin recon →

BENCHMARK — INDIVIDUAL ENTRY

Kitchener

kitchener.ca

SCORE

54/100

GRADE

F

STACK

Custom / non-WordPress

§ I — FINDINGS BY SEVERITY01 / 03

critical

0

high

1

medium

2

low

5

info

1

§ II — SUBJECT FILE02 / 03
target.host
kitchener.ca
tech
Custom / non-WordPress
tls
HTTPS reachable
hsts
1.0 years
spf
present
dmarc
p=quarantine
civic-pages
5/7 categories present
trackers
15 external origins (2 known, 13 unclassified)
§ III — TOP FINDINGS03 / 03
  • high

    Session-replay scripts on a municipal site (Microsoft Clarity)

  • medium

    No Content-Security-Policy

  • medium

    SPF policy is permissive (~all)

  • low

    No MTA-STS policy on kitchener.ca

  • low

    No open-data portal published at kitchener.ca

NEXT STEP

A custom rebuild closes a category of these findings in one purchasing cycle.