Appearance
Report
Each project has a Report — a curated deliverable built from scan findings, LFI Commander files, and Bustah discoveries. Use it to separate “everything the scanners found” from “what we actually want to hand to someone.”
Open a project and choose Report in the sidebar. The badge shows how many report items are in the project (not individual evidence files).
What goes in a report
A report is a list of items. Each item has a title, severity, description, remediation, references (when applicable), and one or more evidence blocks.
| Source | How it gets added | What you get |
|---|---|---|
| Nikto / LFIC scan findings | From Findings — bookmark a row, bulk Add to Report, or toggle in finding detail | One report item per finding, with HTTP request/response evidence snapshotted at add time |
| Technology detection (crawl) | Same as above — add individual tech rows or select a Technologies detected group | One report item per host titled Technologies detected, with one evidence block per technology (each labeled with the product name) |
| LFI Commander retrieved files | From the host LFIC tab results explorer — file+ icon on a file row or in the content viewer | File content added as evidence on a Path Traversal item for that host (one item per host; many files attach as separate evidence entries) |
| Bustah discovery hits | From the host Bustah tab results tree — Add to report on a hit row | One File Found Via Discovery item per host; each path attaches as file evidence (retained response body, not HTTP wire capture) |
Adding something to the report does not mark a Nikto/LFIC finding reviewed. Removing report evidence or items does not delete the underlying finding or retrieved file on the host — only the report copy.
The Report page
The Report section lists items in a compact table, most severe first (critical → info), then by title and host. Click a row, or its ▸, to expand it to the full item:
- Description, remediation, and references (when present)
- Evidence — HTTP request/response pairs for scan findings, or file path + content for LFI Commander files. HTTP evidence headings show the URL (the HTTP method is stripped from the label so the location reads clearly).
- Per-evidence checkboxes for bulk removal (see below), and Remove (✕) on individual evidence blocks
When the report is empty, the page shows No items in the report yet.
Views
The toolbar toggles between two views of the same items:
| View | One row per | Columns |
|---|---|---|
| By host + finding (default) | Report item | Checkbox, Host, Finding, Severity, Delete (trash) |
| By finding | Distinct finding title | Checkbox, Finding, Severity, Count |
In By finding, the severity is the worst among that finding's hosts and Count is how many hosts it appears on. Expand a finding to list one row per host (each with its own checkbox and trash), then expand a host row for the full item.
Expand all opens every row to show every item in full; Collapse all closes them again. The browser remembers your view and expand-all choice.
Select and remove
A toolbar above the list provides:
- Select all — tri-state header checkbox (all / some / none)
- Per-item checkboxes — selecting an item also selects all of its evidence
- Per-finding checkboxes (By finding view) — select every host's instance of that finding at once; shows a partial state when only some are ticked
- Per-evidence checkboxes (in an expanded item) — select whole HTTP evidence entries or Request / Response separately
- Remove Selected — deletes everything ticked (whole items, whole evidence blocks, or individual request/response parts). Confirmation summarizes what will be removed.
Selections carry across views: tick a finding in By finding, switch to By host + finding, and each of its host rows is still ticked.
Use this to trim oversized exports without deleting findings from the project.
Export
Buttons at the top right (disabled when the report is empty):
| Button | What happens |
|---|---|
| HTML | Opens a modal to choose Include request / Include response (both on by default) and whether to Include credentials (passwords/secrets) (off by default — secrets are redacted unless opted in), then opens a self-contained formatted report in a new browser tab (print-friendly). The page starts with a Nikto Platform banner (inline CSS and text; no external fonts or images). |
| Markdown | Same modal, then downloads a .md file named after the project, for example my_project_report.md. |
| JSON | Downloads structured report data for tooling or archival. Always includes full evidence — no include/exclude step. |
The HTML/Markdown modal applies to every HTTP evidence block in the report. File evidence (LFI Commander) is unaffected.
Exports include all report items; unchecked request/response parts are omitted from HTML/Markdown when you untick them in the modal.
HTTP/2 and HTTP/3 findings: HTTP evidence labels are tagged with the negotiated protocol (for example [HTTP/3.0]). Request/response bodies use pseudo-header framing in exports — the same reconstruction as finding detail's default view, not raw HTTP/1.x wire format. See HTTP/3 in reports.
HTML for sharing, Markdown for editing
Use HTML when you want something readable in a browser or printable to PDF from the browser's print dialog. Use Markdown when you want to edit the write-up or check it into version control.
Different from CSV/JSON finding export
Findings Export N downloads raw finding rows (CSV/JSON) for selected findings only. Report HTML / Markdown / JSON are formatted report items with evidence. See Exporting Findings.
Add scan findings from Findings
From the project Findings list (or the same table on a host's Findings tab or a Nikto or crawl scan's results view):
- Click the bookmark+ icon on a row to add one finding.
- Select several findings and click Add to Report N.
- Open finding detail and use the report toggle in the footer.
A finding whose host is not in a project cannot be filed. A single add shows the refusal reason. A bulk add that only partly succeeds reports Report: added N of M; N could not be added; N no longer exist. and does not mark the skipped rows as in-report. See Findings.
On Findings views, rows in the report show a green left border (both reviewed and in-report shows green + blue).
Filter by report status on Findings
On the main Findings page, use the report filter pills:
- ✓ N Report — findings already in the report.
- ✗ N Report — findings not yet added.
Combine with Unreviewed to triage before adding.
Delete hosts and report items
Deleting a host removes its scans and findings. If the host has report items, the delete confirmation offers a checkbox to also delete this host's report item(s). Uncheck it to keep those report entries (they'll still reference the host label/id).