All-in-one free web application security tool. Web application vulnerability and privacy scanner with support for HTTP cookies, Flash, HTML5 localStorage, sessionStorage, CANVAS, Supercookies, Evercookies. Includes a free SSL/TLS, HTML and HTTP vulnerability scanner and URL malware scanner.
Category: News CDN Resource
Keywords: dies duck news next play after first today trump video world carter luverne russian service stories analysis president washington perspective
Last fetched: 2018-02-05T12:41:23.790640+00:00
HTTP status: 5 Sub-resource URL
Content-Security-Policy: upgrade-insecure-requests, upgrade-insecure-requests
Content Security Policy is used by a web server to declare a list of trusted content types (images, scripts, media etc) and origins from which they can be safely loaded as intended by the website authors. The
Content-Security-Policy-Report-Only header instruct the browser to enable CSP in enforcement mode.
Server: Akamai Image Manager
Announces web server software and optionally version details.Read more...
The header sets permissive AJAX access by using wildcard origin
*. It may be OK if the website is a publicly accessible REST API but otherwise it should be not present at all
XmlHttpRequest from a website that is not in the same origin, which is a precaution against various types of data stealing attacks. The target server has to explicitly allow the origin domain using the
Access-Control-Allow-Origin (ACAO) header, or it may allow all origins to access it using a wildcard
*. The latter however creates a potential security issue if the website in question is transactional and processing sensitive data, so the wildcard should be only used on websites consciously offering public APIs.
Transport Layer Security (TLS) is enabled+2
X-Frame-Options header is missing
X-XSS-Protection header is missing
X-Content-Type-Options header is missing
base-uri allows attackers to inject
base tags which override the base URI to an attacker-controlled origin. Set to
'none' unless you need to handle tricky relative URLs scheme
block-all-mixed-content directive if your website is only accessible over TLS and you are certain it doesn not have any legacy plaintext resources. Otherwise you may add adding
upgrade-insecure-requests directive if your website may still have some legacy plaintext HTTP resources and you want them to be still available rather than blocked
upgrade-insecure-requests, is not part of the latest W3C CSP standard
The website uses the following advertisement publisher ids: