https://cash.app/

Eingereichte URL:
https://cash.me/Umgeleitet
Bericht beendet:

Risiken · 0 gefunden

Praktiken, die ein Sicherheitsrisiko darstellen können

  • Ohne Klassifizierung

Security Header · 5 gefunden

HTTP-Antwortheader, die die Sicherheit einer Web-App erhöhen können

NameWertSupportInfo
Strict-Transport-Securitymax-age=631152000; includeSubDomains; preloadGutartig
X-Frame-OptionsSAMEORIGINGutartig
X-Content-Type-OptionsnosniffGutartig
Content-Security-Policydefault-src 'self' https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://squareup.com; style-src 'self' 'unsafe-inline' https://cash-f.squarecdn.com https://cash-c.squarecdn.com 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://fonts.gstatic.com; img-src 'self' data: blob: https://tracker.samplicio.us https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://cash-s.squarecdn.com https://cash-images-f.squarecdn.com https://cash.app https://images.ctfassets.net/ https://images.squareup.com https://jumbotron-production-f.squarecdn.com https://api.squareup.com https://notify.bugsnag.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://api.cash.app https://rs.fullstory.com; media-src 'self' https://videos.ctfassets.net https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://cash-s.squarecdn.com; frame-src 'self' *.google.com https://www.google.ca https://assets.ctfassets.net https://player.vimeo.com squarecash: https://square.com *.google.com; object-src https://assets.ctfassets.net; script-src 'nonce-AMRbJQ6UbG7AUYdhQw7MEx0=' 'self' 'unsafe-inline' https://player.vimeo.com https://cash-f.squarecdn.com https://cash-c.squarecdn.com squarecash: https://squareup.com https://*.googleapis.com https://edge.fullstory.com https://rs.fullstory.com; connect-src 'self' https://api.smartrecruiters.com https://browser-intake-datadoghq.com/api/v2/rum https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://crz5fygf73g7.statuspage.io https://c2nqm6xyr4t4.statuspage.io https://squareup.com https://*.bugsnag.com 'self' https://*.googleapis.com *.google.com https://*.gstatic.com data: blob: https://signal.cash.app https://edge.fullstory.com https://rs.fullstory.com; base-uri 'none'; report-uri /event/csp-report; form-action 'none'Gutartig
Referrer-PolicyGutartig
Clear-Site-DataGutartig
X-Permitted-Cross-Domain-PoliciesGutartig
Permissions-PolicyNeu
Cross-Origin-Embedder-PolicyNeu
Cross-Origin-Opener-PolicyNeu
Cross-Origin-Resource-PolicyNeu
X-XSS-Protection1; mode=blockVeraltet
Feature-PolicyVeraltet
Expect-CTVeraltet
Public-Key-PinsVeraltet

Sicherheitsverstöße · 0 gefunden

Anfragen oder Ressourcen, die gegen Sicherheitsrichtlinien verstoßen

  • Keine gefunden

Zertifikate · 4 gefunden

SSL/TLS-Zertifikate ermöglichen es Websites, Transaktionen zwischen dem Client und dem Server zu verschlüsseln und die Identität des Servers zu überprüfen.

GegenstandAusstellungsdatumAblaufdatum
cash.app18. Feb. 2024, 00:00:0031. Dez. 2024, 23:59:59
cash-f.squarecdn.com16. Okt. 2024, 19:58:4514. Jan. 2025, 19:58:44
images.ctfassets.net19. Dez. 2023, 00:00:0016. Jan. 2025, 23:59:59
assets.ctfassets.net18. Dez. 2023, 00:00:0014. Jan. 2025, 23:59:59