https://cartobio.agencebio.org

Nmap
severity | service | vulnerability |
info | http (port:80) | |
info | http (port:443) | |
info | http (port:8080) | |
info | http (port:8443) |
Mozilla HTTP observatory
Impact | Description | Documentation |
Content Security Policy (CSP) header not implemented | Implement one, see MDN's Content Security Policy (CSP) documentation. | |
| Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/). | |
| Documentation for x-frame-options-sameorigin-or-deny | |
| Documentation for x-content-type-options-nosniff |
SSL
Grade capped to A. HSTS is not offered
Grade capped to B. TLS 1.0 offered
Grade capped to B. TLS 1.1 offered
Expiration : 27/05/2025
Scan OWASP
risk | name |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Medium (Medium) | Missing Anti-clickjacking Header |
Low (High) | Strict-Transport-Security Header Not Set |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Low (Medium) | X-Content-Type-Options Header Missing |
Low (Low) | Timestamp Disclosure - Unix |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Base64 Disclosure |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Retrieved from Cache |
Informational (Medium) | Storable and Cacheable Content |
Informational (Medium) | Storable but Non-Cacheable Content |
Informational (Low) | Information Disclosure - Suspicious Comments |
Informational (Low) | Re-examine Cache-control Directives |