Skip to content

Available Variables

List of project-related variables that can be used in the report template. For example {project.name} will display project name used when creating a project on the platform.

VariableTypeDescription
project.idnumberUnique project identifier
project.uuidstringProject UUID
project.namestringProject name
project.descriptionstringProject description
project.start_atstringProject start date/time
project.end_atstringProject end date/time
project.typestringProject type name
project.scope_typestringProject scope type (internal/external)
extra_fieldsobjectAdditional custom fields

Extra fields usage example:

{project.extra_fields[‘last_name’]}
VariableTypeDescription
client.idnumberClient identifier
client.company_namestringClient company name
client.websitestringClient company’s wesbite
client.contact_namestringClient contact’s name
client.contact_positionstringClient contact’s position
client.contact_phonestringClient contact’s phone
client.contact_emailstringClient contact’s email
client.addressstringClient company’s address
client.citystringClient company’s city
client.countrystringClient company’s country
client.industrystringClient company’s industry
extra_fieldsobjectAdditional custom fields

Extra fields usage example:

{client.extra_fields[‘last_name’]}
VariableTypeDescription
membersarrayList of team members (excluding managers)
members_allarrayList of all team members

Member object:

FieldTypeDescription
idnumberMember ID
namestringMember name
emailstringMember email
typestringMember type
certificatesstringMember certificates
job_titlestringMember job title
phone_numberstringMember phone number
VariableTypeDescription
targetsarrayList of assessment targets
out_of_scopearrayList of out of scope targets

Target object:

FieldTypeDescription
idnumberTarget ID
endpointstringTarget endpoint
notestringTarget note

Usage exmaple:

{#targets}
{endpoint} - {note}
{/targets}
{#out_of_scope}
{endpoint} - {note}
{/out_of_scope}
VariableTypeDescription
report.idnumberReport ID
report.uuidstringReport UUID
report.titlestringReport title
report.versionstringReport version
report.created_atstringReport creation date/time
report.additional_fieldsobjectAdditional custom fields
report.executive_summarystringExecutive summary
report.creatorstringReport creator

Additional fields usage example:

{report.additional_fields['Risk Raiting']}

Creator object:

FieldTypeDescription
idnumberCreator ID
namestringCreator name
emailstringCreator email
typestringCreator type
certificatesstringCreator certificates
job_titlestringCreator job title
phone_numberstringMember phone number
VariableTypeDescription
criticalCountnumberNumber of critical findings
highCountnumberNumber of high findings
mediumCountnumberNumber of medium findings
lowCountnumberNumber of low findings
infoCountnumberNumber of informational findings
criticalCvssCountnumberNumber of critical CVSS findings
highCvssCountnumberNumber of high CVSS findings
mediumCvssCountnumberNumber of medium CVSS findings
lowCvssCountnumberNumber of low CVSS findings
infoCvssCountnumberNumber of informational CVSS findings
findingsTotalCountnumberTotal number of findings
VariableTypeDescription
vulnerabilitiesarrayList of vulnerabilities

Vulnerability object:

FieldTypeDescription
idnumberVulnerability ID
uuidstringVulnerability UUID
titlestringVulnerability title
descriptionstringVulnerability description
pocstringProof of concept
risksstringRisks associated
remediationstringRemediation steps
remediation_stagestringRemediation stage (Not Remediated, Requested, Retesting, Remediated, Partial)
cvssstringCVSS vector
cvss_scorenumberCVSS base score
probabilitystringProbability rating
impactstringImpact rating
has_affected_hostsboolTrue if affected hosts exist
affected_hostsarrayList of affected hosts
categoriesarrayList of category objects
categories_textstringComma-separated category names
categories_text_idsstringCategory IDs (one per line)
categories_idsarrayArray of category IDs
cvss_riskstringRisk level based on CVSS score
extra_fieldsobjectAdditional custom fields
riskstringCriticality rating
cvssRiskstringRisk level based on CVSS score
redBackgroundobjectCell background color info
assessment_domainstringAssessment domain name
order_idnumberOrder index in report
http_excerptsstringVulnerability HTTP Excerpts
has_commentsboolTrue if comments exist
commentsarrayList of comments

Extra fields usage example:

{#vulnerabilities}
{extra_fields['OWASP Context']}
{/vulnerabilities}

Affected host object:

FieldTypeDescription
idnumberHost ID
endpointstringHost endpoint
notestringHost note

Category object:

FieldTypeDescription
idnumberCategory ID
namestringCategory name

Comments object:

FieldTypeDescription
idnumberComment ID
commentatorstringCommentator name
textstringComment text/content
created_atstringComment creation date/time
VariableTypeDescription
manager.idnumberManager ID
manager.namestringManager name
manager.emailstringManager email
VariableTypeDescription
report_datestringDate of report generation