
1,706 Findings, 103 Groups: One Issue, One Card, Everywhere in Your Report
On a large scan, the same underlying issue rarely shows up once. A missing security header, an outdated library, a misconfigured cookie, if it's wrong on your site, it's usually wrong on every page that shares the template. Until now, that meant one finding card per page. Ten near-identical cards for ten pages. Eighty-three for eighty-three.
That was never a detection problem, Decloak was finding the right things. It was a reading problem: the report made you scroll past the same issue, worded identically, over and over, to get to the next distinct thing actually worth your attention.
What changed
Findings that share the same category and title now roll up into a single card, with every affected location listed underneath and one remediation panel instead of one per occurrence. "HSTS header missing" becomes one line, "Affects 83 locations", with the full list one click away, not eighty-three lines saying the same thing.
How it works
Every finding already carries a category and a title, that's the identity of the underlying issue, independent of where it was found. The report now groups findings by that pair before rendering: a single instance still renders as a normal card, more than one collapses into a rollup card showing the representative finding, an "Affects N locations" badge, and an expandable list of every specific page, script, or domain it hit. Remediation is generated once per group and shown once, not regenerated or repeated per occurrence.
This mechanism wasn't new, it shipped first for AI Pentesting findings, where the same nuclei template matching on twenty pages was clearly one bug, not twenty. The work here was auditing every other surface in the report and closing the gaps where it hadn't been wired up yet, along with fixing a couple of details the audit turned up: a case where a finding's own baked-in remediation text was getting silently dropped once it was grouped, and a badge that said "pages" even for findings grouped by script URL, GTM container, or third-party domain, it just says "locations" now, accurately, everywhere.
Where you'll see it
The free report, the free PDF export, the paid multi-page report, the paid PDF and DAST exports, AI Pentesting, Compliance Mapping, and the Priority Remediation Plan.
Every tier, every export format. A one-page free scan benefits the same way a two-hundred-page Enterprise crawl does, the free tier just as often turns up the same dangerous JavaScript pattern on five different scripts on its one page, and that's exactly the kind of repetition this collapses.
Nothing about detection or scoring changed. Same findings, same severities, same score and grade, this is entirely about how they're presented once we've found them.
Why now
This came directly from people running Decloak against real targets, not from a backlog grooming session. When a security professional evaluating the platform tells you their 76-page scan came back as "1,706 findings, 103 groups" and asks why the header issue that's true of the whole site isn't just one line, that's not a feature request, it's a correctness bar. The report should read the way the site actually behaves: one thing wrong, described once, everywhere it's true.
Nothing to do on your end
See it on your next scan. Reload an existing report and any repeated finding already rolls up, no re-scan needed.
Finding grouping is live across every plan, every report type, and every export format. Scan your site free →