https://chat.whatsapp.com/KEiiE2ObZLdAEiBsJjYj46

Submitted URL:
https://chat.whatsapp.com/KEiiE2ObZLdAEiBsJjYj46
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 8 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; preload; includeSubDomainsGood
X-Frame-OptionsDENYGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policydefault-src 'self' data: blob:; script-src *.facebook.com *.fbcdn.net *.whatsapp.com *.whatsapp.net https://*.facebook.net 'nonce-mBZ57Ka0' 'self' data: blob:; style-src 'self' 'unsafe-inline' data: blob: * https://fonts.googleapis.com; connect-src 'self' https://*.whatsapp.com data: blob:; font-src https://*.fbcdn.net https://static.whatsapp.net data: https://fonts.gstatic.com; img-src *; frame-src whatsapp: 'self' data: blob:; block-all-mixed-content; upgrade-insecure-requests; Good
Referrer-PolicyGood
Clear-Site-DataGood
X-Permitted-Cross-Domain-PoliciesGood
Permissions-Policyaccelerometer=(); attribution-reporting=(); autoplay=(); bluetooth=(); camera=(); ch-device-memory=(); ch-downlink=(); ch-dpr=(); ch-ect=(); ch-rtt=(); ch-save-data=(); ch-ua-arch=(); ch-ua-bitness=(); ch-viewport-height=(); ch-viewport-width=(); ch-width=(); clipboard-read=(); clipboard-write=(); compute-pressure=(); display-capture=(); encrypted-media=(); fullscreen=(self); gamepad=(); geolocation=(); gyroscope=(); hid=(); idle-detection=(); interest-cohort=(); keyboard-map=(); local-fonts=(); magnetometer=(); microphone=(); midi=(); otp-credentials=(); payment=(); picture-in-picture=(); private-state-token-issuance=(); publickey-credentials-get=(); screen-wake-lock=(); serial=(); shared-storage=(); shared-storage-select-url=(); private-state-token-redemption=(); usb=(); unload=(self); window-management=(); xr-spatial-tracking=(); report-to="permissions_policy"New
Cross-Origin-Embedder-PolicyNew
Cross-Origin-Opener-Policysame-originNew
Cross-Origin-Resource-Policycross-originNew
X-XSS-Protection0Deprecated
Feature-PolicyDeprecated
Expect-CTDeprecated
Public-Key-PinsDeprecated

Security Violations · 1 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://chat.whatsapp.com/KEiiE2ObZLdAEiBsJjYj46
Description
The Content Security Policy directive 'upgrade-insecure-requests' is ignored when delivered in a report-only policy.
Content Security Policy

Certificates · 1 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
*.whatsapp.netSep 11, 2024, 00:00:00Dec 10, 2024, 23:59:59