Dutch
English
Talk to an Expert

Scan Report

Image-01

100

Good

Wow, amazing grade

Perform a deeper security analysis of your website with a VAPT by WebSec...

Get Consultation

Site

https://demo.checkjc.com

IP Address

2.139.154.227

Report Time

2026-08-07 19:25:42

Security Headers

Upcoming Headers

Data Not Found!

  • Date

    Fri, 07 Aug 2026 19:25:43 GMT


  • Server


  • Content-Security-Policy

    default-src 'none'; style-src 'self' https://data.checkjc.com/checkjc/; script-src 'self' https://data.checkjc.com/checkjc/; font-src 'self' https://data.checkjc.com/checkjc/; img-src 'self' data: https://data.checkjc.com/checkjc/; media-src 'self' https://data.checkjc.com/checkjc/; manifest-src 'self' https://data.checkjc.com/checkjc/; object-src 'none'; connect-src 'self' https://data.checkjc.com/checkjc/; base-uri 'self' https://data.checkjc.com/checkjc/; form-action 'self'; frame-ancestors 'none';


  • Cross-Origin-Resource-Policy

    same-origin


  • Cross-Origin-Opener-Policy

    same-origin


  • Cross-Origin-Embedder-Policy

    credentialless


  • Referrer-Policy

    same-origin


  • Permissions-Policy

    camera=(), microphone=(), geolocation=()


  • Integrity-Policy

    blocked-destinations=(script)


  • Document-Policy

    document-write=?0


  • Cache-Control

    private, no-cache


  • Clear-Site-Data

    "clientHints", "executionContexts", "prefetchCache", "prerenderCache"


  • Upgrade-Insecure-Requests

    1


  • Origin-Agent-Cluster

    : ?1


  • X-DNS-Prefetch-Control

    on


  • X-Permitted-Cross-Domain-Policies

    none


  • X-XSS-Protection

    1; mode=block


  • X-Frame-Options

    deny


  • x-vercel-id

    3d9ba650725a169fe2580709c26dcc4ff4bc7814


  • Strict-Transport-Security

    max-age=31536000; includeSubDomains; preload


  • Set-Cookie

    B9A5A284684754C7_mid=S%3AkjNhEjfGjpo0xRJOOTJ58u--g6ZR2zDzVRQssMUOAHKP2VRTWA4qSAMBgM6zWpSFoAF3WQWHCZzIIG6xawWftrKB9Fl5ZN7Tg0Hi8MoBtK5Zykib-LG4I_9f9-kDDFUyaZEfrLuREh-YVaeFFSdWJpc9iig8e824PhCoY8Oogy-3BE9eFVi58IOUs_9hlew0ApOOxh3xJeX1f80Lu8qXXUEIvpuLaDt_734%3D; expires=Fri, 07 Aug 2026 21:25:43 GMT; Max-Age=7200; path=/;HttpOnly;Secure;SameSite=strict


  • Upgrade

    h2,h2c


  • Connection

    Upgrade, Keep-Alive


  • Vary

    Accept-Encoding


  • Content-Encoding

    gzip


  • X-Content-Type-Options

    nosniff


  • Content-Length

    4852


  • Keep-Alive

    timeout=5, max=100


  • Content-Type

    text/html; charset=UTF-8


  • Cross-Origin-Embedder-Policy

    Allows a site to prevent asset loading without explicit permission via CORS or CORP.

  • Cross-Origin-Opener-Policy

    Helps a site opt into cross-origin isolation.

  • Cross-Origin-Resource-Policy

    Specifies who can load resources from your site.


  • server

    Server value has been changed. Typically you will see values like 'Microsoft-IIS/8.0' or 'nginx 1.7.2'.


  • x-xss-protection

    X-XSS-Protection sets the configuration for the XSS Auditor in older browsers. The recommended value was '1; mode=block' but you should now use Content Security Policy.


  • content-security-policy

    Content Security Policy helps protect your site from XSS attacks. Review your policy using tools such as Report URI.


  • x-frame-options

    X-Frame-Options indicates whether your site can be framed, helping to prevent clickjacking.


  • x-content-type-options

    X-Content-Type-Options prevents browsers from MIME-sniffing the content type. The only valid value is 'nosniff'.


  • referrer-policy

    Referrer Policy allows a site to control how much referrer information is sent with requests.


  • permissions-policy

    Permissions Policy allows a site to control which features and APIs are available.


  • strict-transport-security

    HTTP Strict Transport Security enforces HTTPS and strengthens TLS.


  • vary

    Vary indicates which request headers affect the cached response.


  • date

    Date indicates when the response was generated.

Do you like our scanner?

You can return the favor!