Technology
Security Score
A
91/100

Excellent security posture. Strong in: dns, tls, headers, files, general.

Scanned 3 days ago

Is this your business?

Claim this page to get detailed reports, request re-scans, and manage your profile.

CSP contains unsafe directives
MEDIUM
HEADERS

The CSP includes 'unsafe-inline' or 'unsafe-eval' which weakens protection.

Recommendation: Remove unsafe directives and use nonces or hashes instead.

TLS 1.3 not supported
LOW
TLS

The server does not support TLS 1.3, the latest TLS version.

Recommendation: Enable TLS 1.3 for improved security and performance.

No security.txt found
LOW
FILES

No security.txt file was found. This file helps security researchers contact you.

Recommendation: Add a security.txt file at /.well-known/security.txt per RFC 9116.

Email authentication configured
INFO
DNS

SPF, DMARC, and DKIM are all configured for this domain.

HSTS does not include subdomains
INFO
TLS

HSTS is not applied to subdomains.

Recommendation: Consider adding includeSubDomains to HSTS if applicable.

Good security headers
INFO
HEADERS

Essential security headers (CSP, X-Frame-Options, X-Content-Type-Options) are configured.

No robots.txt found
INFO
FILES

No robots.txt file was found at the root.

Recommendation: Consider adding a robots.txt file to control crawler behavior.