Server 18.6 (Debian 18.6-1.pgdg13+2) · collected 2026-10-01T18:03:36Z (before) and 2026-10-01T18:03:37Z (after)
| Check | Title | Before | After |
| PG-01 | Weak pg_hba authentication | 6 finding(s) | pass |
| PG-02 | MD5 password hashing | 1 finding(s) | pass |
| PG-03 | TLS not enforced | 2 finding(s) | pass |
| PG-04 | Unexpected superusers or privileged app role | 1 finding(s) | pass |
| PG-05 | pg_hba open to any address | 1 finding(s) | pass |
| PG-06 | pgAudit not configured | 1 finding(s) | pass |
| PG-07 | Connection logging incomplete | 3 finding(s) | pass |
| PG-08 | PUBLIC can create in schema public | 1 finding(s) | pass |
| PG-09 | Application role over-privileged | 4 finding(s) | pass |
| PG-10 | SECURITY DEFINER without fixed search_path | 1 finding(s) | pass |
| PG-11 | Untrusted language marked trusted | pass | pass |
| PG-12 | Sensitive column in plaintext | 1 finding(s) | pass |
| Check | Severity | Status | Object | Detail |
| PG-01 | High | Finding | pg_hba line 117 | local all all uses trust. |
| PG-01 | High | Finding | pg_hba line 119 | host all all 127.0.0.1 uses trust. |
| PG-01 | High | Finding | pg_hba line 121 | host all all ::1 uses trust. |
| PG-01 | High | Finding | pg_hba line 124 | local replication all uses trust. |
| PG-01 | High | Finding | pg_hba line 125 | host replication all 127.0.0.1 uses trust. |
| PG-01 | High | Finding | pg_hba line 126 | host replication all ::1 uses trust. |
| PG-02 | Medium | Finding | clinic_app | Password stored as an MD5 hash. |
| PG-03 | High | Finding | ssl | SSL is off; connections cannot be encrypted. |
| PG-03 | High | Finding | pg_hba line 128 | host all all all allows connections without TLS. |
| PG-04 | High | Finding | clinic_app | App role has CREATEDB. |
| PG-05 | Medium | Finding | pg_hba line 128 | host all all all accepts clients from any address. |
| PG-06 | High | Finding | shared_preload_libraries | pgaudit is not preloaded, so no audit records are written. |
| PG-07 | Medium | Finding | log_connections | Connections are not logged. |
| PG-07 | Medium | Finding | log_disconnections | Disconnections are not logged. |
| PG-07 | Medium | Finding | log_line_prefix | log_line_prefix lacks user, database, client. |
| PG-08 | Medium | Finding | clinic | PUBLIC has CREATE on schema public. |
| PG-09 | Medium | Finding | public.patients | Owned by the app role; an owner can alter or drop it. |
| PG-09 | Medium | Finding | public.patients_id_seq | Owned by the app role; an owner can alter or drop it. |
| PG-09 | Medium | Finding | public.appointments | Owned by the app role; an owner can alter or drop it. |
| PG-09 | Medium | Finding | public.appointments_id_seq | Owned by the app role; an owner can alter or drop it. |
| PG-10 | High | Finding | public.patient_count | SECURITY DEFINER function without a fixed search_path. |
| PG-12 | Medium | Finding | public.patients.national_id | Stored as text (plaintext); expected pgcrypto-encrypted bytea. |