https://tllms.com/

Submitted URL:
https://tllms.com
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 6 found

HTTP response headers that can harden the security of a web application

Learn more...
NameValueSupportInfo
Strict-Transport-Securitymax-age=631138519GoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-Optionsallow-from 'self' https://*.byjus.com https://byjus.com http://*.byjusweb.com https://*.tllms.com https://tllms.com https://www.google.com https://*.aakashdigital.com https://aakashdigital.com https://*.byjusresources.com https://byjusresources.comGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsnosniffGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policydefault-src 'self' https:; connect-src 'self' stats.byjus.com streaming.byjus.com *.amazonaws.com byju.pc.cdn.bitgravity.com d2gfdr9obzcioh.cloudfront.net byjus.akamaized.net byjus-in.akamaized-staging.net byjus-in.akamaized.net gcdn.byjus.com bfs-gcdn.byjus.com gcdn-staging.byjus.com bfs-gcdn-staging.byjus.com byjus-k3-vod.akamaized.net *.tllms.com; font-src 'self' https: data:; frame-ancestors 'self' *.byjus.com byjus.com *.byjusweb.com *.tllms.com tllms.com www.google.com *.aakashdigital.com aakashdigital.com *.byjusresources.com byjusresources.com; frame-src 'self' *.byjus.com/ byjus.com *.tllms.com tllms.com www.youtube.com www.google.com *.aakashdigital.com aakashdigital.com *.byjusresources.com byjusresources.com; img-src 'self' https: data: http: blob:; media-src 'self' blob: streaming.byjus.com byju.pc.cdn.bitgravity.com byjus.akamaized.net byjus-in.akamaized-staging.net byjus-in.akamaized.net gcdn.byjus.com bfs-gcdn.byjus.com gcdn-staging.byjus.com bfs-gcdn-staging.byjus.com byjus-k3-vod.akamaized.net *.tllms.com; object-src 'none'; script-src https: 'self' 'unsafe-eval' 'unsafe-inline' www.google-analytics.com cdnjs.cloudflare.com js-agent.newrelic.com www.google.com www.googleadservices.com k12questions.tllms.com; style-src 'self' https: 'unsafe-inline'GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-PolicyGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesnoneGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-PolicyNewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-Protection1; mode=blockDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 1 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://www.google-analytics.com/analytics.js
Description
Refused to connect to 'https://www.google-analytics.com/j/collect?v=1&_v=j101&a=1777750132&t=pageview&_s=1&dl=https%3A%2F%2Ftllms.com%2F&ul=en-us&de=UTF-8&dt=Byju%27s&sd=24-bit&sr=1x1&vp=790x600&je=0&_u=IEBAAEABAAAAACAAI~&jid=834886044&gjid=322633878&cid=1303643125.1728458459&tid=UA-61876819-1&_gid=506636773.1728458459&_r=1&_slc=1&z=1384903261' because it violates the following Content Security Policy directive: "connect-src 'self' stats.byjus.com streaming.byjus.com *.amazonaws.com byju.pc.cdn.bitgravity.com d2gfdr9obzcioh.cloudfront.net byjus.akamaized.net byjus-in.akamaized-staging.net byjus-in.akamaized.net gcdn.byjus.com bfs-gcdn.byjus.com gcdn-staging.byjus.com bfs-gcdn-staging.byjus.com byjus-k3-vod.akamaized.net *.tllms.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...

Certificates · 5 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
*.tllms.comFeb 6, 2024, 00:00:00Mar 6, 2025, 23:59:59
*.cloudfront.netJul 30, 2024, 00:00:00Jul 3, 2025, 23:59:59
upload.video.google.comSep 16, 2024, 09:34:31Dec 9, 2024, 09:34:30
*.google-analytics.comSep 16, 2024, 08:55:43Dec 9, 2024, 08:55:42
*.gstatic.comSep 16, 2024, 09:34:31Dec 9, 2024, 09:34:30