Retail
Security Score
C
73/100

Moderate security posture. Several improvements recommended. 1 high severity issue found. Strong in: dns, tls, files, general.

Scanned 6 days ago

Is this your business?

Claim this page to get detailed reports, request re-scans, and manage your profile.

Outdated TLS protocol
HIGH
TLS

The server does not support TLS 1.2 or 1.3.

Recommendation: Enable TLS 1.2 and TLS 1.3 support.

Missing X-Content-Type-Options
MEDIUM
HEADERS

No X-Content-Type-Options header found.

Recommendation: Add X-Content-Type-Options: nosniff header.

Missing CAA records
LOW
DNS

No CAA records found. CAA records specify which CAs can issue certificates.

Recommendation: Add CAA records to restrict certificate issuance to trusted CAs.

Missing Referrer-Policy
LOW
HEADERS

No Referrer-Policy header found.

Recommendation: Add a Referrer-Policy header (e.g., strict-origin-when-cross-origin).

Missing Permissions-Policy
LOW
HEADERS

No Permissions-Policy header found.

Recommendation: Add a Permissions-Policy header to control browser features.

Server version disclosed
LOW
HEADERS

The Server header reveals version information: Microsoft-IIS/10.0

Recommendation: Configure the server to hide version information.

X-Powered-By header present
LOW
HEADERS

Technology stack disclosed: ASP.NET

Recommendation: Remove the X-Powered-By header to hide technology stack.

No security.txt found
LOW
FILES

No security.txt file was found. This file helps security researchers contact you.

Recommendation: Add a security.txt file at /.well-known/security.txt per RFC 9116.

Email authentication configured
INFO
DNS

SPF, DMARC, and DKIM are all configured for this domain.

HSTS does not include subdomains
INFO
TLS

HSTS is not applied to subdomains.

Recommendation: Consider adding includeSubDomains to HSTS if applicable.

No robots.txt found
INFO
FILES

No robots.txt file was found at the root.

Recommendation: Consider adding a robots.txt file to control crawler behavior.