Paramètres d'affichage

Choisissez un thème pour personnaliser l'apparence du site.

Nmap

Scan Summary :

A

severityservicevulnerability

info

http (port:80)

info

https (port:443)
Consulter le rapport détaillé

Mozilla HTTP observatory

Scan Summary :

F

ImpactDescriptionDocumentation

-30

Session cookie set without using the HttpOnly flag.

Documentation for cookies-secure-with-httponly-sessions

-25

Content Security Policy (CSP) header not implemented

-20

Strict-Transport-Security header not implemented.

Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/).

-20

X-Frame-Options (XFO) header not implemented.

Documentation for x-frame-options-sameorigin-or-deny

-5

X-Content-Type-Options header not implemented.

Documentation for x-content-type-options-nosniff

Rapport détaillé

SSL

Scan Summary :

A


Grade capped to A. HSTS is not offered


Expiration : 21/05/2025

Rapport détaillé

Scan OWASP5 jours

riskname

Medium (High)

Content Security Policy (CSP) Header Not Set

Medium (High)

Sub Resource Integrity Attribute Missing

Medium (Medium)

Missing Anti-clickjacking Header

Medium (Low)

Absence of Anti-CSRF Tokens

Low (High)

Strict-Transport-Security Header Not Set

Low (Medium)

Big Redirect Detected (Potential Sensitive Information Leak)

Low (Medium)

Cookie No HttpOnly Flag

Low (Medium)

Cookie with SameSite Attribute None

Low (Medium)

Cookie without SameSite Attribute

Low (Medium)

Cross-Domain JavaScript Source File Inclusion

Low (Medium)

Insufficient Site Isolation Against Spectre Vulnerability

Low (Medium)

Permissions Policy Header Not Set

Low (Medium)

Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)

Low (Medium)

X-Content-Type-Options Header Missing

Low (Low)

Dangerous JS Functions

Low (Low)

Full Path Disclosure

Low (Low)

Timestamp Disclosure - Unix

Informational (High)

Authentication Request Identified

Informational (High)

Sec-Fetch-Dest Header is Missing

Informational (High)

Sec-Fetch-Mode Header is Missing

Informational (High)

Sec-Fetch-Site Header is Missing

Informational (High)

Sec-Fetch-User Header is Missing

Informational (Medium)

Base64 Disclosure

Informational (Medium)

Modern Web Application

Informational (Medium)

Non-Storable Content

Informational (Medium)

Session Management Response Identified

Informational (Medium)

Storable and Cacheable Content

Informational (Low)

Information Disclosure - Suspicious Comments

Informational (Low)

Re-examine Cache-control Directives

Informational (Low)

User Controllable HTML Element Attribute (Potential XSS)

Rapport détaillé

Nuclei5 jours

SéveritéNameMatcher

info

CAA Recordcaa-fingerprint

info

PHP Detectphp-detect

info

Find Pages with Old Copyright Datesold-copyright

info

HTTP Missing Security Headersclear-site-data

info

HTTP Missing Security Headerscross-origin-embedder-policy

info

HTTP Missing Security Headerscross-origin-resource-policy

info

HTTP Missing Security Headersstrict-transport-security

info

HTTP Missing Security Headerspermissions-policy

info

HTTP Missing Security Headersx-frame-options

info

HTTP Missing Security Headersx-content-type-options

info

HTTP Missing Security Headersx-permitted-cross-domain-policies

info

HTTP Missing Security Headersreferrer-policy

info

HTTP Missing Security Headerscross-origin-opener-policy

info

HTTP Missing Security Headerscontent-security-policy

info

Detect SSL Certificate Issuerssl-issuer

info

SSL DNS Namesssl-dns-names

info

TLS Version - Detecttls-version

info

TLS Version - Detecttls-version