https://cash.app/$laurc0

Submitted URL:
https://cash.app/$laurc0
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 5 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=631152000; includeSubDomains; preloadGood
X-Frame-OptionsSAMEORIGINGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policydefault-src 'self' https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://squareup.com; style-src 'self' 'unsafe-inline' https://cash-f.squarecdn.com https://cash-c.squarecdn.com 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://cash-s.squarecdn.com https://cash-images-f.squarecdn.com https://cash.app https://images.ctfassets.net/ https://images.squareup.com https://jumbotron-production-f.squarecdn.com https://api.squareup.com https://notify.bugsnag.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://api.cash.app; font-src 'self' https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://fonts.gstatic.com; frame-src 'self' *.google.com https://www.google.ca squarecash: https://square.com *.google.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; script-src 'nonce-AJ85y4DaFYLydMPw29SLh6Y=' 'self' 'unsafe-inline' https://cash-f.squarecdn.com https://cash-c.squarecdn.com squarecash: https://squareup.com https://*.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; connect-src 'self' https://browser-intake-datadoghq.com/api/v2/rum https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://crz5fygf73g7.statuspage.io https://c2nqm6xyr4t4.statuspage.io https://squareup.com https://*.bugsnag.com 'self' https://*.googleapis.com *.google.com https://*.gstatic.com data: blob: https://signal.cash.app; media-src https://cash-f.squarecdn.com https://cash-c.squarecdn.com https://cash-s.squarecdn.com; base-uri 'none'; report-uri /event/csp-report; form-action 'none'Good
Referrer-PolicyGood
Clear-Site-DataGood
X-Permitted-Cross-Domain-PoliciesGood
Permissions-PolicyNew
Cross-Origin-Embedder-PolicyNew
Cross-Origin-Opener-PolicyNew
Cross-Origin-Resource-PolicyNew
X-XSS-Protection1; mode=blockDeprecated
Feature-PolicyDeprecated
Expect-CTDeprecated
Public-Key-PinsDeprecated

Security Violations · 0 found

Requests or resources offending security policies

  • None found

Certificates · 2 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
cash.appFeb 18, 2024, 00:00:00Dec 31, 2024, 23:59:59
cash-f.squarecdn.comOct 16, 2024, 19:58:45Jan 14, 2025, 19:58:44