https://www.axelspringer.com/de/

Submitted URL:
https://axelspringer.com/Redirected
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 4 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; Good
X-Frame-OptionsSAMEORIGINGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policybase-uri 'www.axelspringer.com'; upgrade-insecure-requests 1; Good
Referrer-PolicyGood
Clear-Site-DataGood
X-Permitted-Cross-Domain-PoliciesGood
Permissions-PolicyNew
Cross-Origin-Embedder-PolicyNew
Cross-Origin-Opener-PolicyNew
Cross-Origin-Resource-PolicyNew
X-XSS-ProtectionDeprecated
Feature-PolicyDeprecated
Expect-CTDeprecated
Public-Key-PinsDeprecated

Security Violations · 4 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://www.axelspringer.com/de/
Description
The Content Security Policy directive 'upgrade-insecure-requests' should be empty, but was delivered with a value of '1'. The directive has been applied, and the value ignored.
Content Security Policy
Resource
https://www.axelspringer.com/de/
Description
The Content Security Policy directive 'upgrade-insecure-requests' should be empty, but was delivered with a value of '1'. The directive has been applied, and the value ignored.
Content Security Policy
Resource
https://www.axelspringer.com/de/
Description
The Content Security Policy directive 'upgrade-insecure-requests' should be empty, but was delivered with a value of '1'. The directive has been applied, and the value ignored.
Content Security Policy
Resource
https://cmp.axelspringer.com/wrapperMessagingWithoutDetection.js
Description
The Content Security Policy directive 'upgrade-insecure-requests' should be empty, but was delivered with a value of '1'. The directive has been applied, and the value ignored.
Content Security Policy

Certificates · 2 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
www.axelspringer.comSep 1, 2024, 00:00:00Sep 30, 2025, 23:59:59
cmp.autobild.deNov 7, 2024, 12:20:13Feb 5, 2025, 12:20:12