Mozilla HTTP observatory
Scan Summary :
Impact | Description | Documentation |
Content Security Policy (CSP) header not implemented | Implement one, see MDN's Content Security Policy (CSP) documentation. | |
| Documentation for x-frame-options-sameorigin-or-deny |
SSL
Scan Summary :
Grade capped to T. Issues with the chain of trust (chain incomplete)
Expiration : 18/11/2023
Scan OWASP
risk | name |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Medium (High) | Sub Resource Integrity Attribute Missing |
Medium (Medium) | Multiple X-Frame-Options Header Entries |
Low (High) | CSP: X-WebKit-CSP |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Low (Low) | Timestamp Disclosure - Unix |
Informational (High) | Obsolete Content Security Policy (CSP) Header Found |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Base64 Disclosure |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Storable and Cacheable Content |
Informational (Low) | Information Disclosure - Suspicious Comments |
Informational (Low) | Re-examine Cache-control Directives |
Nuclei
Séverité | Name | Matcher |
info | CAA Record | caa-fingerprint |
info | Allowed Options Method | options-method |
info | XSS-Protection Header - Cross-Site Scripting | xss-deprecated-header |
info | Apache Detection | apache-detect |
info | Wappalyzer Technology Detection | font-awesome |
info | HTTP Missing Security Headers | cross-origin-opener-policy |
info | HTTP Missing Security Headers | cross-origin-resource-policy |
info | HTTP Missing Security Headers | content-security-policy |
info | HTTP Missing Security Headers | permissions-policy |
info | HTTP Missing Security Headers | referrer-policy |
info | HTTP Missing Security Headers | clear-site-data |
info | HTTP Missing Security Headers | cross-origin-embedder-policy |
info | Missing Subresource Integrity | missing-sri |
info | WAF Detection | apachegeneric |
info | Detect SSL Certificate Issuer | ssl-issuer |
info | SSL DNS Names | ssl-dns-names |
info | TLS Version - Detect | tls-version |
low | Untrusted Root Certificate - Detect | untrusted-root-certificate |