Nmap
severity | service | vulnerability |
info | http (port:80) | |
info | https (port:443) |
Mozilla HTTP observatory
Impact | Description | Documentation |
Content Security Policy (CSP) header not implemented | Implement one, see MDN's Content Security Policy (CSP) documentation. | |
Redirects, but final destination is not an HTTPS URL. | Documentation for redirection-to-https | |
| HSTS can only work with a valid TLS certificate on the server. Let's Encrypt is a good choice, as are certificates managed by your cloud provider or commercially sold ones. |
SSL
Grade capped to A. HSTS is not offered
Grade capped to T. Certificate expired
Grade capped to T. Issues with the chain of trust (expired)
Expiration : 01/08/2024
Scan OWASP
risk | name |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Low (High) | CSP: X-WebKit-CSP |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Low (Low) | Timestamp Disclosure - Unix |
Informational (High) | Obsolete Content Security Policy (CSP) Header Found |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Base64 Disclosure |
Informational (Medium) | Content-Type Header Missing |
Informational (Medium) | Information Disclosure - Suspicious Comments |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Non-Storable Content |
Informational (Medium) | Retrieved from Cache |
Informational (Medium) | Storable and Cacheable Content |