Mozilla HTTP observatory
Scan Summary :
Impact | Description | Documentation |
Doc Content Security Policy. L'extension github.com/april/laboratory permet de générer la CSP pour votre application. | ||
Doc header Strict-Transport-Security (HSTS). | ||
Doc header X-Frame-Options. | ||
Doc header X-Content-Type-Options. |
Scan OWASP
risk | name |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Medium (Medium) | Missing Anti-clickjacking Header |
Low (High) | Strict-Transport-Security Header Not Set |
Low (Medium) | Permissions Policy Header Not Set |
Low (Medium) | X-Content-Type-Options Header Missing |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Storable and Cacheable Content |
Informational (Low) | Information Disclosure - Suspicious Comments |
Informational (Low) | Re-examine Cache-control Directives |