Scan Report

100
Wow, amazing grade
Perform a deeper security analysis of your website with a VAPT by WebSec...
Get ConsultationSite
https://demo.checkjc.com
IP Address
2.139.154.227
Report Time
2026-08-07 19:25:42
Security Headers
Upcoming Headers
- Date
Fri, 07 Aug 2026 19:25:43 GMT
- Server
- Content-Security-Policy
default-src 'none'; style-src 'self' https://data.checkjc.com/checkjc/; script-src 'self' https://data.checkjc.com/checkjc/; font-src 'self' https://data.checkjc.com/checkjc/; img-src 'self' data: https://data.checkjc.com/checkjc/; media-src 'self' https://data.checkjc.com/checkjc/; manifest-src 'self' https://data.checkjc.com/checkjc/; object-src 'none'; connect-src 'self' https://data.checkjc.com/checkjc/; base-uri 'self' https://data.checkjc.com/checkjc/; form-action 'self'; frame-ancestors 'none';
- Cross-Origin-Resource-Policy
same-origin
- Cross-Origin-Opener-Policy
same-origin
- Cross-Origin-Embedder-Policy
credentialless
- Referrer-Policy
same-origin
- Permissions-Policy
camera=(), microphone=(), geolocation=()
- Integrity-Policy
blocked-destinations=(script)
- Document-Policy
document-write=?0
- Cache-Control
private, no-cache
- Clear-Site-Data
"clientHints", "executionContexts", "prefetchCache", "prerenderCache"
- Upgrade-Insecure-Requests
1
- Origin-Agent-Cluster
: ?1
- X-DNS-Prefetch-Control
on
- X-Permitted-Cross-Domain-Policies
none
- X-XSS-Protection
1; mode=block
- X-Frame-Options
deny
- x-vercel-id
3d9ba650725a169fe2580709c26dcc4ff4bc7814
- Strict-Transport-Security
max-age=31536000; includeSubDomains; preload
- Set-Cookie
B9A5A284684754C7_mid=S%3AkjNhEjfGjpo0xRJOOTJ58u--g6ZR2zDzVRQssMUOAHKP2VRTWA4qSAMBgM6zWpSFoAF3WQWHCZzIIG6xawWftrKB9Fl5ZN7Tg0Hi8MoBtK5Zykib-LG4I_9f9-kDDFUyaZEfrLuREh-YVaeFFSdWJpc9iig8e824PhCoY8Oogy-3BE9eFVi58IOUs_9hlew0ApOOxh3xJeX1f80Lu8qXXUEIvpuLaDt_734%3D; expires=Fri, 07 Aug 2026 21:25:43 GMT; Max-Age=7200; path=/;HttpOnly;Secure;SameSite=strict
- Upgrade
h2,h2c
- Connection
Upgrade, Keep-Alive
- Vary
Accept-Encoding
- Content-Encoding
gzip
- X-Content-Type-Options
nosniff
- Content-Length
4852
- Keep-Alive
timeout=5, max=100
- Content-Type
text/html; charset=UTF-8
- Cross-Origin-Embedder-Policy
Allows a site to prevent asset loading without explicit permission via CORS or CORP.
- Cross-Origin-Opener-Policy
Helps a site opt into cross-origin isolation.
- Cross-Origin-Resource-Policy
Specifies who can load resources from your site.
- server
Server value has been changed. Typically you will see values like 'Microsoft-IIS/8.0' or 'nginx 1.7.2'.
- x-xss-protection
X-XSS-Protection sets the configuration for the XSS Auditor in older browsers. The recommended value was '1; mode=block' but you should now use Content Security Policy.
- content-security-policy
Content Security Policy helps protect your site from XSS attacks. Review your policy using tools such as Report URI.
- x-frame-options
X-Frame-Options indicates whether your site can be framed, helping to prevent clickjacking.
- x-content-type-options
X-Content-Type-Options prevents browsers from MIME-sniffing the content type. The only valid value is 'nosniff'.
- referrer-policy
Referrer Policy allows a site to control how much referrer information is sent with requests.
- permissions-policy
Permissions Policy allows a site to control which features and APIs are available.
- strict-transport-security
HTTP Strict Transport Security enforces HTTPS and strengthens TLS.
- vary
Vary indicates which request headers affect the cached response.
- date
Date indicates when the response was generated.