https://www.kk-kyowa.co.jp/edu-serv/s-cme.html

Submitted URL:
https://smart-cme.jp/Redirected
Report Finished:

Risks · 0 found

  • No classification

Security Headers · 4 found

NameValueSupportInfo
Strict-Transport-Securitymax-age=604800GoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsSAMEORIGINGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsnosniffGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policydefault-src https://www.kk-kyowa.co.jp; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://*.google-analytics.com https://www.googleadservices.com https://www.google.com https://ajax.googleapis.com https://googleads.g.doubleclick.net https://al-s.dc-tag.jp https://cdn.audiencedata.net https://cdn.cookie.sync.usonar.jp https://cdn.id5-sync.com https://cdn.kitchen.juicer.cc https://*.treasuredata.com https://dmp.im-apps.net https://kitchen.juicer.cc https://s.dc-tag.jp https://www.clarity.ms https://c.clarity.ms https://panel.interactive-circle.jp https://*.beusable.net https://vjs.zencdn.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://vjs.zencdn.net; style-src-elem 'self' 'unsafe-inline' https://*.googleapis.com https://*.zencdn.net; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.jp https://googleads.g.doubleclick.net https://google.com https://a.ddli.jp https://in.treasuredata.com https://*.s3-ap-northeast-1.amazonaws.com https://panel.interactive-circle.jp https://s.amazon-adsystem.com https://sync.im-apps.net https://sync.logly.co.jp https://tg.socdm.com https://*.clarity.ms https://match.adsrvr.org https://*.tapad.com https://secure.adnxs.com http://*.s3.amazonaws.com https://a.o2u.jp https://id5-sync.com https://*.bing.com data:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://t.dc-tag.jp https://kitchen.juicer.cc https://b.im-apps.net https://al-a.dc-tag.jp https://audiencedata.im-apps.net https://*.clarity.ms https://id5-sync.com https://lb.eu-1-id5-sync.com https://*.beusable.net https://panel.interactive-circle.jp; frame-src 'self' https://*.doubleclick.net https://www.google.com; frame-ancestors 'self'; worker-src 'self' blob:; object-src 'none'; GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-PolicyGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-PolicyNewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-ProtectionDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 3 found

ViolationTypeInfo
Resource
https://www.kk-kyowa.co.jp/edu-serv/s-cme.html
Description
Failed to find a valid digest in the 'integrity' attribute for resource 'https://fonts.googleapis.com/css?family=Raleway:100,300,400,500,700,900' with computed SHA-384 integrity 'TfWCuFF9c9qick3OAxHHe6owkIcFnkaj8eu+4Z1XnzcpWfiQkwlZSJcidC1evwrh'. The resource has been blocked.
Subresource IntegrityEnables browsers to verify that resources fetched are not manipulated.

Click to learn more...
Resource
https://www.kk-kyowa.co.jp/edu-serv/s-cme.html
Description
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-TJ6TZTD2BE&cid=1931370975.1729271235&gtm=45je4ah0v893244859z89105956704za200zb9105956704&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=101529666~101686685~101836706&tag_exp=101529666~101686685~101836706&z=1117352929' because it violates the following Content Security Policy directive: "img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.jp https://googleads.g.doubleclick.net https://google.com https://a.ddli.jp https://in.treasuredata.com https://*.s3-ap-northeast-1.amazonaws.com https://panel.interactive-circle.jp https://s.amazon-adsystem.com https://sync.im-apps.net https://sync.logly.co.jp https://tg.socdm.com https://*.clarity.ms https://match.adsrvr.org https://*.tapad.com https://secure.adnxs.com http://*.s3.amazonaws.com https://a.o2u.jp https://id5-sync.com https://*.bing.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.kk-kyowa.co.jp/edu-serv/s-cme.html
Description
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-K2RD3Y3TSK&cid=1931370975.1729271235&gtm=45je4ah0v9140652783z89105956704za200zb9105956704&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=101686685&tag_exp=101686685&z=1670676709' because it violates the following Content Security Policy directive: "img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.jp https://googleads.g.doubleclick.net https://google.com https://a.ddli.jp https://in.treasuredata.com https://*.s3-ap-northeast-1.amazonaws.com https://panel.interactive-circle.jp https://s.amazon-adsystem.com https://sync.im-apps.net https://sync.logly.co.jp https://tg.socdm.com https://*.clarity.ms https://match.adsrvr.org https://*.tapad.com https://secure.adnxs.com http://*.s3.amazonaws.com https://a.o2u.jp https://id5-sync.com https://*.bing.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...

Certificates · 8 found

SubjectIssue dateExpiry date
*.kk-kyowa.co.jpJan 28, 2024, 00:00:00Feb 26, 2025, 23:59:59
upload.video.google.comSep 30, 2024, 15:09:59Dec 23, 2024, 15:09:58
*.google-analytics.comSep 30, 2024, 14:36:15Dec 23, 2024, 14:36:14
www.clarity.msSep 4, 2024, 00:00:00Sep 4, 2025, 23:59:59
*.g.doubleclick.netSep 30, 2024, 14:36:12Dec 23, 2024, 14:36:11
*.gstatic.comSep 30, 2024, 15:09:59Dec 23, 2024, 15:09:58
a.clarity.msJun 23, 2024, 10:17:34Jun 18, 2025, 10:17:34
juicer.ccDec 24, 2023, 00:00:00Jan 21, 2025, 23:59:59