This scan was made by Website Security Scanner at webscanner.unofix.no
Security headers are HTTP response headers that tell the browser how to handle a websiteβs content in a secure way.
5 of 8 recommended security headers found (77% score)
| Header | Status | Value | Description |
|---|---|---|---|
X-Frame-Options |
β | SAMEORIGIN | Protects against clickjacking attacks. Hackers can load your page in an invisible iframe and trick users into clicking buttons they cannot see (e.g. "Transfer money"). Value: SAMEORIGIN. Assessment: Good. |
X-Content-Type-Options |
β | nosniff | Prevents MIME-sniffing. A malicious file pretending to be an image can be executed as JavaScript and steal user data. Value: nosniff. Assessment: Good. |
Strict-Transport-Security |
β | max-age=31536000 | Enforces HTTPS usage (HSTS). Without HTTPS, attackers on the same WiFi network can intercept all communication and steal passwords in plain text. Value: max-age=31536000. Assessment: Good. Notes: includeSubDomains is not set (optional, but recommended if all subdomains use HTTPS). |
Content-Security-Policy |
β | frame-ancestors 'self' *.canva.com canva.com; report-uri https://csp.canva.com/_cspreport?app=websites; base-uri 'self'; object-src 'none'; script-src 'report-sample' 'strict-dynamic' 'nonce-865d749b-850b-483e-9520-1602f4b1e7f1' https://www.google.com/recaptcha/api.js; | Controls which resources can be loaded. Malicious scripts from third parties can run on your page and steal user data or spread malware. Value: frame-ancestors 'self' *.canva.com canva.com; report-uri https://csp.canva.com/_cspreport?app=websites; base-uri 'self'; object-src 'none'; script-src 'report-sample' 'strict-dynamic' 'nonce-865d749b-850b-483e-9520-1602f4b1e7f1' https://www.google.com/recaptcha/api.js;. Assessment: Good. |
Referrer-Policy |
β | strict-origin-when-cross-origin | Controls what referrer information is sent. Sensitive URLs (e.g. /reset-password?token=abc123) can leak to third parties via analytics or ads. Value: strict-origin-when-cross-origin. Assessment: Good. |
Permissions-Policy |
β | Not set | Controls access to browser features (camera, microphone, GPS). Malicious code or third-party scripts can secretly activate camera/microphone and spy on the user. Status: Not set. |
Cross-Origin-Opener-Policy |
β | Not set | Isolates your window from cross-origin windows. A malicious popup window can read data from your page via window.opener and steal sensitive information. Status: Not set. |
Cross-Origin-Resource-Policy |
β | Not set | Controls who can load your resources. Other websites can steal bandwidth by hotlinking to your images, or read pixel data from cross-origin images. Status: Not set. |
No exposed files or directories found. Checked 49 file locations and 6 directories.
Valid SSL certificate from trusted Certificate Authority. Certificate expires in 89 days.
| Status | β Valid |
|---|---|
| Issued To | arteemarquivo.com.br |
| Issued By | WR1 |
| Valid Until | 2026-05-28 05:37:19 |
| Days Until Expiry | 89 days |
1 of 1 cookie(s) are missing recommended security flags (70% score)
| Cookie Name | Security Flags | Score | Risk | Issues |
|---|---|---|---|---|
__cf_bmOhL6...7Gxk |
π Secureπ‘οΈ HttpOnlyβ SameSite |
70% | π‘ MEDIUM |
|
1 server information header(s) disclosed. Consider hiding these to reduce attack surface.
| Header | Status | Value | Risk |
|---|---|---|---|
Server |
β Exposed | cloudflare | Server software disclosed (cloudflare) but no version number. Consider hiding this header completely. |
X-Powered-By |
β Hidden | Not present | Header not present (good - no information disclosure) |
X-AspNet-Version |
β Hidden | Not present | Header not present (good - no information disclosure) |
X-AspNetMvc-Version |
β Hidden | Not present | Header not present (good - no information disclosure) |
X-Generator |
β Hidden | Not present | Header not present (good - no information disclosure) |