Persistent report
perfectbilisim.com.tr security headers report
Last analyzed:
Available again in 5:00
Score history
2 days · min 75 · max 75 · 0
URL
https://perfectbilisim.com.tr/
Status
200
HTTPS
HTTPS
To-do, by priority
Fails first, then warnings. Tips are things this HTML fetch cannot see.
HSTSPassmax-age=31536000; includeSubDomains
+
max-age=31536000; includeSubDomains
Why it matters: Tells browsers to skip HTTP entirely on the next visit.
Content-Security-PolicyErrorNo CSP
+
No CSP
Why it matters: Limits which scripts, frames and connections the page may use.
What to do
Start with default-src 'self' and add the origins you actually need. Avoid unsafe-inline if you can.
ClickjackingErrorMissing
+
Missing
Why it matters: X-Frame-Options or CSP frame-ancestors stop other sites framing yours.
What to do
Send X-Frame-Options: DENY (or SAMEORIGIN), or frame-ancestors in CSP.
X-Content-Type-OptionsPassnosniff
+
nosniff
Why it matters: nosniff stops the browser guessing MIME types for scripts and styles.
Referrer-PolicyPassstrict-origin-when-cross-origin
+
strict-origin-when-cross-origin
Why it matters: Controls how much of the URL leaks to the next site.
Permissions-PolicyInfoNot set
+
Not set
Why it matters: Restricts camera, geolocation, and similar APIs. Optional.
Cross-Origin-Opener-PolicyInfoNot set
+
Not set
Why it matters: Isolates the browsing context from window.opener. Optional.
Cross-Origin-Resource-PolicyInfoNot set
+
Not set
Why it matters: Stops other sites embedding this response. Optional.
X-XSS-ProtectionPassNot set
+
Not set
Why it matters: Deprecated. Modern browsers ignore it; a leftover 1; mode=block can cause issues.
X-Powered-ByPassNot sent
+
Not sent
Why it matters: Advertises the stack to scanners. Not a ranking factor.
ServerInfocloudflare
+
cloudflare
Why it matters: Often a version string. Informational fingerprint.
Security headers sent
- server
- cloudflare
- referrer-policy
- strict-origin-when-cross-origin
- x-content-type-options
- nosniff
- strict-transport-security
- max-age=31536000; includeSubDomains
Cookie flags (values omitted)
| Name | Secure | HttpOnly | SameSite |
|---|---|---|---|
| __cf_bm | yes | yes | none |
Get this report by email on a schedule, with what changed since last time.

