System Audit
The System Audit page (/system-audit, admin-only) is an on-demand
host security assessment – a distinct thing from the Health page’s “is
everything currently running” live status, or Reports’ usage/analytics
trends. System Audit answers “is the server configured safely”,
producing a point-in-time snapshot (an audit run) you can compare against
the previous one.
What it checks
Section titled “What it checks”Three categories, each made up of individual pass/fail checks:
- System configuration – OS/kernel info, a world-writable file scan of security-sensitive locations, file permissions, and timezone
- SSH hardening –
sshd_config(and drop-ins) directives, host key andauthorized_keysfile permissions - Firewall configuration –
ufw/firewalldstatus and the OpenVPN-managed iptables unit this project’s own installer writes
Every check reports pass or fail individually with plain-language remediation guidance, and some findings offer a one-click Fix Automatically action right on the finding, gated behind the same permission as running the audit itself.
Security Score
Section titled “Security Score”Each audit run produces a 0-100 Security Score:
- Starts at 100
- -25 per Critical finding
- -10 per High finding
- -4 per Medium finding
- -1 per Low finding
- Informational and Passed findings never affect the score
The score is floored at 0, and each run is compared against the previous one so you can see at a glance whether your posture is improving or regressing.
Developed by Cloudlative