Persistent report

perfectbilisim.com.tr security headers report

Last analyzed:

Available again in 5:00

Score history

2 days · min 75 · max 75 · 0

02550751004 Oct · 75/100 (B)6 Oct · 75/100 (B)4 Oct6 Oct

URL

https://perfectbilisim.com.tr/

Status

200

HTTPS

HTTPS

To-do, by priority

Fails first, then warnings. Tips are things this HTML fetch cannot see.

HSTSPass

max-age=31536000; includeSubDomains

+

Why it matters: Tells browsers to skip HTTP entirely on the next visit.

Content-Security-PolicyError

No CSP

+

Why it matters: Limits which scripts, frames and connections the page may use.

1

What to do

Start with default-src 'self' and add the origins you actually need. Avoid unsafe-inline if you can.

ClickjackingError

Missing

+

Why it matters: X-Frame-Options or CSP frame-ancestors stop other sites framing yours.

1

What to do

Send X-Frame-Options: DENY (or SAMEORIGIN), or frame-ancestors in CSP.

X-Content-Type-OptionsPass

nosniff

+

Why it matters: nosniff stops the browser guessing MIME types for scripts and styles.

Referrer-PolicyPass

strict-origin-when-cross-origin

+

Why it matters: Controls how much of the URL leaks to the next site.

Permissions-PolicyInfo

Not set

+

Why it matters: Restricts camera, geolocation, and similar APIs. Optional.

Cross-Origin-Opener-PolicyInfo

Not set

+

Why it matters: Isolates the browsing context from window.opener. Optional.

Cross-Origin-Resource-PolicyInfo

Not set

+

Why it matters: Stops other sites embedding this response. Optional.

X-XSS-ProtectionPass

Not set

+

Why it matters: Deprecated. Modern browsers ignore it; a leftover 1; mode=block can cause issues.

X-Powered-ByPass

Not sent

+

Why it matters: Advertises the stack to scanners. Not a ranking factor.

ServerInfo

cloudflare

+

Why it matters: Often a version string. Informational fingerprint.

CookiesPass

1

+

Why it matters: On HTTPS, cookies without Secure can leak on a downgrade. SameSite stops most CSRF.

Security headers sent

server
cloudflare
referrer-policy
strict-origin-when-cross-origin
x-content-type-options
nosniff
strict-transport-security
max-age=31536000; includeSubDomains

Cookie flags (values omitted)

NameSecureHttpOnlySameSite
__cf_bmyesyesnone

Get this report by email on a schedule, with what changed since last time.