Nmap
Mozilla HTTP observatory
Impact | Description | Documentation |
Content Security Policy (CSP) header not implemented | Implement one, see MDN's Content Security Policy (CSP) documentation. | |
Does not redirect to an HTTPS site. | Documentation for redirection-to-https | |
| Make your site available over HTTPS. Let's Encrypt docs are a good starting point. | |
| Documentation for x-frame-options-sameorigin-or-deny | |
| Documentation for x-content-type-options-nosniff |
Scan OWASP
risk | name |
High (Medium) | Vulnerable JS Library |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Medium (Medium) | Missing Anti-clickjacking Header |
Low (High) | Server Leaks Version Information via "Server" HTTP Response Header Field |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Low (Medium) | Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) |
Low (Medium) | X-Content-Type-Options Header Missing |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Storable and Cacheable Content |
Informational (Low) | Charset Mismatch (Header Versus Meta Content-Type Charset) |
Informational (Low) | Information Disclosure - Suspicious Comments |
Nuclei
Séverité | Name | Matcher |
info | CAA Record | caa-fingerprint |
info | Apache Detection | apache-detect |
info | Openssl Detect | openssl-detect |
info | PHP Detect | php-detect |
info | Wappalyzer Technology Detection | php |
info | HTTP Missing Security Headers | x-content-type-options |
info | HTTP Missing Security Headers | x-permitted-cross-domain-policies |
info | HTTP Missing Security Headers | referrer-policy |
info | HTTP Missing Security Headers | clear-site-data |
info | HTTP Missing Security Headers | cross-origin-opener-policy |
info | HTTP Missing Security Headers | cross-origin-resource-policy |
info | HTTP Missing Security Headers | content-security-policy |
info | HTTP Missing Security Headers | permissions-policy |
info | HTTP Missing Security Headers | cross-origin-embedder-policy |
info | HTTP Missing Security Headers | strict-transport-security |
info | HTTP Missing Security Headers | x-frame-options |
info | HTTP TRACE method enabled | trace-request |
info | WAF Detection | apachegeneric |
info | OpenSSH Service - Detect | openssh-detect |
info | Detect SSL Certificate Issuer | ssl-issuer |
info | SSL DNS Names | ssl-dns-names |
info | TLS Version - Detect | tls-version |