Persistent report

pintelly.com security headers report

Last analyzed:

Available again in 5:00

Score history

2 days · min 67 · max 67 · 0

025507510011 Sept · 67/100 (C)18 Sept · 67/100 (C)11 Sept18 Sept

URL

https://pintelly.com/

Status

200

HTTPS

HTTPS

To-do, by priority

Fails first, then warnings. Tips are things this HTML fetch cannot see.

HSTSError

No HSTS

+

Why it matters: Tells browsers to skip HTTP entirely on the next visit.

1

What to do

Send Strict-Transport-Security with max-age of at least 15552000 (180 days).

Content-Security-PolicyError

No CSP

+

Why it matters: Limits which scripts, frames and connections the page may use.

1

What to do

Start with default-src 'self' and add the origins you actually need. Avoid unsafe-inline if you can.

ClickjackingPass

sameorigin

+

Why it matters: X-Frame-Options or CSP frame-ancestors stop other sites framing yours.

X-Content-Type-OptionsPass

nosniff

+

Why it matters: nosniff stops the browser guessing MIME types for scripts and styles.

Referrer-PolicyPass

same-origin

+

Why it matters: Controls how much of the URL leaks to the next site.

Permissions-PolicyInfo

Not set

+

Why it matters: Restricts camera, geolocation, and similar APIs. Optional.

Cross-Origin-Opener-PolicyInfo

Not set

+

Why it matters: Isolates the browsing context from window.opener. Optional.

Cross-Origin-Resource-PolicyInfo

Not set

+

Why it matters: Stops other sites embedding this response. Optional.

X-XSS-ProtectionInfo

1; mode=block

+

Why it matters: Deprecated. Modern browsers ignore it; a leftover 1; mode=block can cause issues.

X-Powered-ByPass

Not sent

+

Why it matters: Advertises the stack to scanners. Not a ranking factor.

ServerInfo

cloudflare

+

Why it matters: Often a version string. Informational fingerprint.

CookiesInfo

No Set-Cookie

+

Why it matters: On HTTPS, cookies without Secure can leak on a downgrade. SameSite stops most CSRF.

Security headers sent

server
cloudflare
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-xss-protection
1; mode=block
x-content-type-options
nosniff

Get this report by email on a schedule, with what changed since last time.