Submitted URL:
Report Finished:
  • No classification
  • Not set
Strict-Transport-SecurityGoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-PolicyGoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-PolicyGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-PolicyNewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-ProtectionDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...
Access to XMLHttpRequest at '' from origin '' has been blocked by CORS policy: The value of the 'Access-Control-Allow-Credentials' header in the response is '' which must be 'true' when the request's credentials mode is 'include'. The credentials mode of requests initiated by the XMLHttpRequest is controlled by the withCredentials attribute.
Cross-Origin Resource SharingControls which external origins are allowed load resources.

Click to learn more...
SubjectIssue dateExpiry date
baomoi.comJan 15, 2024, 00:00:00Jan 23, 2025, 23:59:59
*.bmcdn.meMar 13, 2024, 00:00:00Mar 23, 2025, 23:59:59
*.zalo.meJul 2, 2024, 00:00:00Jul 12, 2025, 23:59:59
*.zadn.vnMar 21, 2024, 00:00:00Mar 21, 2025, 23:59:59
*.zdn.vnJul 8, 2024, 00:00:00Jul 17, 2025, 23:59:59
*.zascdn.meOct 21, 2024, 00:00:00Oct 27, 2025, 23:59:59
*.api.adtimaserver.vnApr 22, 2024, 00:00:00Apr 21, 2025, 23:59:59
*.google-analytics.comDec 2, 2024, 08:35:56Feb 24, 2025, 08:35:55
*.baochinhphu.vnJan 12, 2024, 01:56:11Feb 12, 2025, 01:56:10
*.g.doubleclick.netDec 2, 2024, 08:35:56Feb 24, 2025, 08:35:55