Paramètres d'affichage

Choisissez un thème pour personnaliser l'apparence du site.

https://ma-cantine.agriculture.gouv.fr

Accompagner les acteurs de la restauration collective pour proposer une alimentation de qualité, saine et durable
environ 9 heures

dinum

fiche beta.gouv.fr

Copie d'écran de https://ma-cantine.agriculture.gouv.fr

Nmap

Scan Summary :

B

severityservicevulnerability

info

http (port:80)

info

bgp (port:179)

info

https (port:443)

info

socks (port:1080)

info

pvuniwien (port:1081)

info

abyss (port:9999)
Consulter le rapport détaillé

Mozilla HTTP observatory

Scan Summary :

D+

ImpactDescriptionDocumentation

-20

Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.

Remove unsafe-inline and data: from script-src, overly broad sources from object-src and script-src, and ensure object-src and script-src are set.

-20

Cookies set without using the Secure flag or set over HTTP.

Documentation for cookies-secure-with-httponly-sessions

-20

Strict-Transport-Security header not implemented.

Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/).

Rapport détaillé

SSL

Scan Summary :

F


Grade capped to A. HSTS is not offered


Expiration : 10/07/2025

Rapport détaillé

Scan OWASPenviron 9 heures

riskname

Medium (High)

CSP: Failure to Define Directive with No Fallback

Medium (High)

CSP: Wildcard Directive

Medium (High)

CSP: script-src unsafe-inline

Medium (High)

CSP: style-src unsafe-inline

Low (High)

Strict-Transport-Security Header Not Set

Low (Medium)

Cookie No HttpOnly Flag

Low (Medium)

Cookie Without Secure Flag

Low (Medium)

Insufficient Site Isolation Against Spectre Vulnerability

Low (Medium)

Permissions Policy Header Not Set

Low (Medium)

Vulnerable JS Library

Low (Medium)

X-Content-Type-Options Header Missing

Low (Low)

Timestamp Disclosure - Unix

Informational (High)

Sec-Fetch-Dest Header is Missing

Informational (High)

Sec-Fetch-Mode Header is Missing

Informational (High)

Sec-Fetch-Site Header is Missing

Informational (High)

Sec-Fetch-User Header is Missing

Informational (Medium)

Base64 Disclosure

Informational (Medium)

Modern Web Application

Informational (Medium)

Session Management Response Identified

Informational (Medium)

Storable and Cacheable Content

Informational (Low)

Information Disclosure - Suspicious Comments

Informational (Low)

Re-examine Cache-control Directives

Rapport détaillé