https://owasp.org/www-project-juice-shop/

ID da verificação
54bc6009-3f45-4681-b4a4-78c526a4aba1Concluído
URL enviado:
https://owasp.org/www-project-juice-shop/
Relatório concluído:

Riscos · 0 encontrados

Práticas que podem representar riscos de segurança

  • Sem classificação

Cabeçalhos de segurança · 6 encontrados

Cabeçalhos de resposta HTTP que podem reforçar a segurança de uma aplicação web

NomeValorApoio ao clienteInformação
Strict-Transport-Securitymax-age=31536000; includeSubDomainsBom
X-Frame-OptionsSAMEORIGINBom
X-Content-Type-OptionsnosniffBom
Content-Security-Policydefault-src 'self' https://*.fontawesome.com https://api.github.com https://*.githubusercontent.com https://*.google-analytics.com https://owaspadmin.azurewebsites.net https://*.twimg.com https://platform.twitter.com https://www.youtube.com https://*.doubleclick.net; frame-ancestors 'self'; frame-src https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.sched.com https://*.google.com https://*.twitter.com https://www.youtube.com https://w.soundcloud.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://viewer.diagrams.net https://fonts.googleapis.com https://*.fontawesome.com https://app.diagrams.net https://cdnjs.cloudflare.com https://cse.google.com https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.youtube.com https://*.meetup.com https://*.sched.com https://*.google-analytics.com https://unpkg.com https://buttons.github.io https://www.google.com https://*.gstatic.com https://*.twitter.com https://*.twimg.com; style-src 'self' 'unsafe-inline' https://*.gstatic.com https://cdnjs.cloudflare.com https://www.google.com https://fonts.googleapis.com https://platform.twitter.com https://*.twimg.com data:; font-src 'self' https://*.fontawesome.com fonts.gstatic.com; manifest-src 'self' https://pay.google.com; img-src 'self' https://*.globalappsec.org https://render.com https://*.render.com https://okteto.com https://*.okteto.com data: www.w3.org https://*.bestpractices.dev https://licensebuttons.net https://img.shields.io https://*.twitter.com https://github.githubassets.com https://*.twimg.com https://platform.twitter.com https://*.githubusercontent.com https://*.vercel.app https://*.cloudfront.net https://*.coreinfrastructure.org https://*.securityknowledgeframework.org https://badges.gitter.im https://travis-ci.org https://api.travis-ci.org https://s3.amazonaws.com https://snyk.io https://coveralls.io https://requires.io https://github.com https://*.googleapis.com https://*.google.com https://*.gstatic.comBom
Referrer-Policysame-originBom
Clear-Site-DataBom
X-Permitted-Cross-Domain-PoliciesBom
Permissions-Policygeolocation=(self)Novo
Cross-Origin-Embedder-PolicyNovo
Cross-Origin-Opener-PolicyNovo
Cross-Origin-Resource-PolicyNovo
X-XSS-ProtectionDescontinuado
Feature-PolicyDescontinuado
Expect-CTDescontinuado
Public-Key-PinsDescontinuado

Violações de segurança · 0 encontradas

Pedidos ou recursos que ofendem as políticas de segurança

  • Nenhum encontrado

Certificados · 8 encontrados

Os certificados SSL/TLS permitem que os sites encriptem transações entre o cliente e o servidor e forneçam a verificação de identidade do servidor

AssuntoData de emissãoData de validade
owasp.org26/09/2024, 22:43:5925/12/2024, 22:43:58
*.google-analytics.com30/09/2024, 14:36:1523/12/2024, 14:36:14
*.github.io15/03/2024, 00:00:0014/03/2025, 23:59:59
shields.io21/10/2024, 02:11:4219/01/2025, 02:11:41
www.bestpractices.dev16/09/2024, 17:14:3115/12/2024, 17:14:30
*.cloudfront.net30/07/2024, 00:00:003/07/2025, 23:59:59
*.vercel.app17/10/2024, 00:02:1415/01/2025, 00:02:13
*.soundcloud.com6/02/2024, 12:22:159/03/2025, 12:22:14