https://stgw.hodo.in/

Submitted URL:
https://stgw.hodo.in/
Report Finished:

Risks · 0 found

Copy link

Practices that may pose security risks

  • No classification

Security Headers · 7 found

Copy link

HTTP response headers that can harden the security of a web application

Learn more...
NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preloadGoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsSAMEORIGINGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsnosniffGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policydefault-src 'self'; font-src *; img-src * data:; script-src * 'unsafe-inline'; style-src * 'unsafe-inline'; default-src 'self'; font-src *; img-src * data:; script-src * 'unsafe-inline'; style-src * 'unsafe-inline'; GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-Policystrict-originGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-Data—GoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-Policies—GoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-Policygeolocation=(); microphone=(); camera=(); payment=()NewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-Policy—NewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-Policy—NewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-Policy—NewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-Protection1; mode=blockDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-Policy—DeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CT—DeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-Pins—DeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 21 found

Copy link

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Refused to load the font 'data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3...OnYercZg2YVmLN/d/gczfEimrE/fs/bOuq29Zmn8tloORaXgZgGa78yO9/cnXm2BpaGvq25Dv9S4E9+5SIc9PqupJKhYFSSl47+Qcr1mYNAAAAeNptw0cKwkAAAMDZJA8Q7OUJvkLsPfZ6zFVERPy8qHh2YER+3i/BP83vIBLLySsoKimrqKqpa2hp6+jq6RsYGhmbmJqZSy0sraxtbO3sHRydnEMU4uR6yx7JJXveP7WrDycAAAAAAAH//wACeNpjYGRgYOABYhkgZgJCZgZNBkYGLQZtIJsFLMYAAAw3ALgAeNolizEKgDAQBCchRbC2sFER0YD6qVQiBCv/H9ezGI6Z5XBAw8CBK/m5iQQVauVbXLnOrMZv2oLdKFa8Pjuru2hJzGabmOSLzNMzvutpB3N42mNgZGBg4GKQYzBhYMxJLMlj4GBgAYow/P/PAJJhLM6sSoWKfWCAAwDAjgbRAAB42mNgYGBkAIIbCZo5IPrmUn0hGA0AO8EFTQAA' because it violates the following Content Security Policy directive: "font-src *". Note that '*' matches only URLs with network schemes ('http', 'https', 'ws', 'wss'), or URLs whose scheme matches `self`'s scheme. The scheme 'data:' must be added explicitly.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Refused to load the font 'data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3...OnYercZg2YVmLN/d/gczfEimrE/fs/bOuq29Zmn8tloORaXgZgGa78yO9/cnXm2BpaGvq25Dv9S4E9+5SIc9PqupJKhYFSSl47+Qcr1mYNAAAAeNptw0cKwkAAAMDZJA8Q7OUJvkLsPfZ6zFVERPy8qHh2YER+3i/BP83vIBLLySsoKimrqKqpa2hp6+jq6RsYGhmbmJqZSy0sraxtbO3sHRydnEMU4uR6yx7JJXveP7WrDycAAAAAAAH//wACeNpjYGRgYOABYhkgZgJCZgZNBkYGLQZtIJsFLMYAAAw3ALgAeNolizEKgDAQBCchRbC2sFER0YD6qVQiBCv/H9ezGI6Z5XBAw8CBK/m5iQQVauVbXLnOrMZv2oLdKFa8Pjuru2hJzGabmOSLzNMzvutpB3N42mNgZGBg4GKQYzBhYMxJLMlj4GBgAYow/P/PAJJhLM6sSoWKfWCAAwDAjgbRAAB42mNgYGBkAIIbCZo5IPrmUn0hGA0AO8EFTQAA' because it violates the following Content Security Policy directive: "font-src *". Note that '*' matches only URLs with network schemes ('http', 'https', 'ws', 'wss'), or URLs whose scheme matches `self`'s scheme. The scheme 'data:' must be added explicitly.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Refused to frame 'https://www.google.com/' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Refused to frame 'https://www.google.com/' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://www.google-analytics.com/analytics.js
Description
Refused to connect to 'https://www.google-analytics.com/j/collect?v=1&_v=j101&a=1790271219&t=pageview&_s=1&dl=https%3A%2F%2Fstgw.hodo.in%2F&ul=en-us&de=UTF-8&dt=at-home&sd=24-bit&sr=1x1&vp=790x600&je=0&_u=YEBAAUABAAAAACAAI~&jid=1669796878&gjid=72528155&cid=355627158.1736343486&tid=UA-163825152-9&_gid=105819989.1736343486&_r=1&gtm=457e4cc1za200&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102198178&jsscut=1&npa=1&z=2062940474' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.google-analytics.com/analytics.js
Description
Refused to connect to 'https://www.google-analytics.com/j/collect?v=1&_v=j101&a=1790271219&t=pageview&_s=1&dl=https%3A%2F%2Fstgw.hodo.in%2F&ul=en-us&de=UTF-8&dt=at-home&sd=24-bit&sr=1x1&vp=790x600&je=0&_u=YEBAAUABAAAAACAAI~&jid=1669796878&gjid=72528155&cid=355627158.1736343486&tid=UA-163825152-9&_gid=105819989.1736343486&_r=1&gtm=457e4cc1za200&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102198178&jsscut=1&npa=1&z=2062940474' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security PolicyControls resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure element 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request was not upgraded to HTTPS because its URL's host is an IP address.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...
Resource
https://stgw.hodo.in/
Description
Mixed Content: The page at 'https://stgw.hodo.in/' was loaded over HTTPS, but requested an insecure image 'http://192.168.50.210:8123/jasim/uploads/198/06b6b1397fab139085788af176824e46.jpg'. This request has been blocked; the content must be served over HTTPS.
Mixed ContentBlocks unencrypted content from loading in an encrypted page.

Click to learn more...

Certificates · 9 found

Copy link

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
*.hodo.inAug 16, 2024, 00:00:00Sep 16, 2025, 23:59:59
use.fontawesome.comJan 5, 2025, 23:52:55Apr 6, 2025, 00:52:49
upload.video.google.comDec 2, 2024, 08:36:58Feb 24, 2025, 08:36:57
cdnjs.cloudflare.comNov 26, 2024, 07:25:18Feb 24, 2025, 07:25:17
www.google.comDec 2, 2024, 08:37:44Feb 24, 2025, 08:37:43
bootstrapcdn.comNov 18, 2024, 00:43:34Feb 16, 2025, 00:43:33
*.google-analytics.comDec 2, 2024, 08:35:56Feb 24, 2025, 08:35:55
*.gstatic.comDec 2, 2024, 08:36:58Feb 24, 2025, 08:36:57
*.hotjar.comMay 22, 2024, 00:00:00Jun 20, 2025, 23:59:59