https://punchng.com/

Submitted URL:
https://punchng.com/
Report Finished:

Risks · 0 found

Copy link

Practices that may pose security risks

  • No classification

Security Headers · 0 found

Copy link

HTTP response headers that can harden the security of a web application

Learn more...
  • Not set
NameValueSupportInfo
Strict-Transport-Security—GoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-Options—GoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-Options—GoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policy—GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-Policy—GoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-Data—GoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-Policies—GoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-Policy—NewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-Policy—NewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-Policy—NewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-Policy—NewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-Protection—DeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-Policy—DeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CT—DeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-Pins—DeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 1 found

Copy link

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://punchng.com/
Description
Access to XMLHttpRequest at 'https://bam.eu01.nr-data.net/1/NRJS-e0417124bb2c226b0f6?a=270273138&v=1.277.0&to=MhBSZQoZWUVYBRZaWwtacVIMEVhYFg4NXlEVFFdU&rst=1463&ck=0&s=6a58598dfb4f1800&ref=https://punchng.com/&ptid=89997244ebeb57ea&af=err,spa,xhr,stn,ins&ap=42162&be=96&fe=828&dc=436&at=HldRE0IDSks%3D&fsh=1&perf=%7B%22timing%22:%7B%22of%22:1737935218423,%22n%22:0,%22f%22:1,%22dn%22:1,%22dne%22:1,%22c%22:50,%22s%22:59,%22ce%22:79,%22rq%22:79,%22rp%22:97,%22rpe%22:116,%22di%22:448,%22ds%22:532,%22de%22:532,%22dc%22:876,%22l%22:876,%22le%22:924%7D,%22navigation%22:%7B%7D%7D&fp=375&fcp=375' from origin 'https://punchng.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
Cross-Origin Resource SharingControls which external origins are allowed load resources.

Click to learn more...

Certificates · 22 found

Copy link

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
punchng.com
*.google-analytics.com
c.amazon-adsystem.com
upload.video.google.com
heyzine.com
*.gstatic.com
*.onesignal.com
*.smartocto.com
*.google.com
*.g.doubleclick.net