All-in-one free web application security tool. Web application vulnerability and privacy scanner with support for HTTP cookies, Flash, HTML5 localStorage, sessionStorage, CANVAS, Supercookies, Evercookies. Includes a free SSL/TLS, HTML and HTTP vulnerability scanner and URL malware scanner.
Keywords: x27 life news says after first house sport stuff trump world years people winston zealand auckland business feedback opinion: wellington
Last fetched: 2019-07-19T08:30:06.099272+00:00
HTTP status: 5 Sub-resource URL
Announces web server software and optionally version details.Read more...
Transport Layer Security (TLS) is enabled+2
X-Frame-Options header is missing
X-XSS-Protection header is missing
X-Content-Type-Options header is missing
default-src https: data: blob: 'unsafe-inline' 'unsafe-eval' 'report-sample'; img-src http: https: data: blob:; media-src http: https: data: blob:; report-uri https://csp-reporter-production.apse2.ffx.nz/
base-uri allows attackers to inject
base tags which override the base URI to an attacker-controlled origin. Set to
'none' unless you need to handle tricky relative URLs scheme
block-all-mixed-content directive if your website is only accessible over TLS and you are certain it doesn not have any legacy plaintext resources. Otherwise you may add adding
upgrade-insecure-requests directive if your website may still have some legacy plaintext HTTP resources and you want them to be still available rather than blocked
default-src data: origin allows bypassing CSP and execution of inlined untrusted scripts
default-src 'unsafe-inline' allows bypassing of CSP and execution of inlined untrusted scripts. Use
default-src 'unsafe-eval' allows bypassing of CSP and execution of inlined untrusted scripts. Use
Want second opinion? Try Google CSP Evaluator.
The website uses the following advertisement publisher ids: