https://www.maybank2u.com.my/home/m2u/common/login.do

Submitted URL:
https://www.maybank2u.com.my/home/m2u/common/login.do
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 5 found

HTTP response headers that can harden the security of a web application

Learn more...
NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; includeSubDomainsGoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsSAMEORIGINGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsNOSNIFFGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policydefault-src 'self' wss://*.cyberstock.com.my wss://*.maybank2u.com.my *.maybank2u.com.my *.google-analytics.com *.googlesyndication.com *.doubleclick.net *.useinsider.com https://perfectsencollector.com *.google.com https://analytics.google.com *.googleapis.com *.googletagmanager.com https://*.maybankheart.com; object-src *.maybank2u.com.my; style-src 'self' 'unsafe-inline' *.googleapis.com *.google.com; style-src-elem 'self' 'unsafe-inline' *.googleapis.com *.google.com *.gstatic.com; font-src *.gstatic.com *.maybank2u.com.my *.google.com *.mobiletrade.powerbroking2u.com.my; script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my; frame-src 'self' *.maybank2u.com.my *.useinsider.com https://unity.cadreon.com *.doubleclick.net *.youtube.com *.google.com *.mobiletrade.powerbroking2u.com.my *.cyberstock.com.my; img-src 'self' data: blob: *.maybank2u.com.my https://emerchant.maybank2u.com.my:8443 *.google-analytics.com *.googlesyndication.com *.doubleclick.net https://www.google.com https://www.google.com.my https://www.google.com.sg https://www.google.co.in https://www.google.co.id https://www.facebook.com/tr/ *.useinsider.com www.maybank.com *.gstatic.com *.googleapis.com http://dbv47yu57n5vf.cloudfront.net https://perfectsencollector.com *.amazonaws.com *.oto.my *.googletagmanager.com *.youtube.comGoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-PolicyGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-PolicyNewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-Protection1; MODE=BLOCKDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 11 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://www.googletagmanager.com/gtm.js?id=GTM-KHWJN5G
Description
Refused to load the script 'https://snap.licdn.com/li.lms-analytics/insight.min.js' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=CGD6KE3C77UCVI78RGPG&lib=ttq' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=CGD6KE3C77UCVI78RGPG&lib=ttq' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://bat.bing.com/bat.js' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://s.yimg.com/wi/ytc.js' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://secure.quantserve.com/quant.js' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Description
Refused to load the script 'https://static.ads-twitter.com/uwt.js' because it violates the following Content Security Policy directive: "script-src 'self' *.maybank2u.com.my *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com 'unsafe-inline' 'unsafe-eval' *.doubleclick.net *.mbww.com *.useinsider.com https://connect.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.cyberstock.com.my". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.maybank2u.com.my/home/m2u/common/login.do
Description
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-17SZKT8CR4&cid=1121023181.1727233992&gtm=45je49n0v887464565z878200465za200zb78200465&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=0&tag_exp=0&z=176807012' because it violates the following Content Security Policy directive: "img-src 'self' data: blob: *.maybank2u.com.my https://emerchant.maybank2u.com.my:8443 *.google-analytics.com *.googlesyndication.com *.doubleclick.net https://www.google.com https://www.google.com.my https://www.google.com.sg https://www.google.co.in https://www.google.co.id https://www.facebook.com/tr/ *.useinsider.com www.maybank.com *.gstatic.com *.googleapis.com http://dbv47yu57n5vf.cloudfront.net https://perfectsencollector.com *.amazonaws.com *.oto.my *.googletagmanager.com *.youtube.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.maybank2u.com.my/home/m2u/common/login.do
Description
Refused to load the image 'https://www.google.es/pagead/1p-conversion/931442049/?random=1238800242&cv=11&fst=1727233992227&bg=ffffff&guid=ON&async=1&gtm=45be49n0v888080683za200&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101671035&u_w=1&u_h=1&url=https%3A%2F%2Fwww.maybank2u.com.my%2Fhome%2Fm2u%2Fcommon%2Flogin.do&label=gGZgCIbC0uwDEIHbkrwD&hn=www.googleadservices.com&frm=0&tiba=Maybank2u%20%7C%20Maybank%20Malaysia&npa=1&pscdl=noapi&auid=351929840.1727233991&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=SA&data=event%3Dconversion&fmt=3&ct_cookie_present=false&crd=CLHBsQIIsMGxAgi5wbECCLHDsQIIisWxAgjqxrEC&pscrd=IhMIxuS3hJDdiAMV2mKkBB078DV6MgIIAzICCAQyAggHMgIICDICCAkyAggKMgIIAjICCAsyAggVMgIIHzICCBMyAggSOh1odHRwczovL3d3dy5tYXliYW5rMnUuY29tLm15Lw&is_vtc=1&cid=CAQSGwDpaXnfAQFdUY4XWaf0XqI4t3tc1ttUbxP8Hw&random=1546864187&ipr=y' because it violates the following Content Security Policy directive: "img-src 'self' data: blob: *.maybank2u.com.my https://emerchant.maybank2u.com.my:8443 *.google-analytics.com *.googlesyndication.com *.doubleclick.net https://www.google.com https://www.google.com.my https://www.google.com.sg https://www.google.co.in https://www.google.co.id https://www.facebook.com/tr/ *.useinsider.com www.maybank.com *.gstatic.com *.googleapis.com http://dbv47yu57n5vf.cloudfront.net https://perfectsencollector.com *.amazonaws.com *.oto.my *.googletagmanager.com *.youtube.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.maybank2u.com.my/home/m2u/common/login.do
Description
Refused to load the image 'https://www.google.es/pagead/1p-conversion/931442049/?random=1977639399&cv=11&fst=1727233992741&bg=ffffff&guid=ON&async=1&gtm=45be49n0v888080683z878200465za201zb78200465&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=0&u_w=1&u_h=1&url=https%3A%2F%2Fwww.maybank2u.com.my%2Fhome%2Fm2u%2Fcommon%2Flogin.do&label=TuIKCKCFsuYDEIHbkrwD&hn=www.googleadservices.com&frm=0&tiba=Maybank2u%20%7C%20Maybank%20Malaysia&value=0&npa=1&pscdl=noapi&auid=351929840.1727233991&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=SA&fmt=3&ct_cookie_present=false&crd=CLHBsQIIsMGxAgi5wbECCLHDsQIIisWxAgijxbEC&pscrd=IhMIg_HUhJDdiAMVW1GkBB1zsQj6MgIIAzICCAQyAggHMgIICDICCAkyAggKMgIIAjICCAsyAggVMgIIHzICCBMyAggSOh1odHRwczovL3d3dy5tYXliYW5rMnUuY29tLm15Lw&is_vtc=1&cid=CAQSKQDpaXnf1NTzh-hVe38d6QQmiEtZk3cq2f3teeYMaFILSM2QkQCRQXYB&eitems=ChAI8MbJtwYQnov6zenRwpVmEh0ApmzywlRJuxCumphT7IdR1XIMi5yEMo5HzW8nVg&random=1036269911&ipr=y' because it violates the following Content Security Policy directive: "img-src 'self' data: blob: *.maybank2u.com.my https://emerchant.maybank2u.com.my:8443 *.google-analytics.com *.googlesyndication.com *.doubleclick.net https://www.google.com https://www.google.com.my https://www.google.com.sg https://www.google.co.in https://www.google.co.id https://www.facebook.com/tr/ *.useinsider.com www.maybank.com *.gstatic.com *.googleapis.com http://dbv47yu57n5vf.cloudfront.net https://perfectsencollector.com *.amazonaws.com *.oto.my *.googletagmanager.com *.youtube.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.maybank2u.com.my/home/m2u/common/login.do
Description
Refused to load the image 'https://www.google.es/pagead/1p-conversion/931442049/?random=984388606&cv=11&fst=1727233993384&bg=ffffff&guid=ON&async=1&gtm=45be49n0v888080683za200&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101671035&u_w=1&u_h=1&url=https%3A%2F%2Fwww.maybank2u.com.my%2Fhome%2Fm2u%2Fcommon%2Flogin.do&label=gGZgCIbC0uwDEIHbkrwD&hn=www.googleadservices.com&frm=0&tiba=Maybank2u%20%7C%20Maybank%20Malaysia&npa=1&pscdl=noapi&auid=351929840.1727233991&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=SA&data=event%3Dconversion&fmt=3&ct_cookie_present=false&crd=CLHBsQIIsMGxAgi5wbECCLHDsQIIisWxAgiRybEC&pscrd=IhMIrt77hJDdiAMVOlekBB3dnQZIMgIIAzICCAQyAggHMgIICDICCAkyAggKMgIIAjICCAsyAggVMgIIHzICCBMyAggSOh1odHRwczovL3d3dy5tYXliYW5rMnUuY29tLm15Lw&is_vtc=1&cid=CAQSKQDpaXnfEp1iOinxKpojylsyUFZZmhJ5SSmweT8UvukMGtmMUBjUQC5L&random=1535162897&ipr=y' because it violates the following Content Security Policy directive: "img-src 'self' data: blob: *.maybank2u.com.my https://emerchant.maybank2u.com.my:8443 *.google-analytics.com *.googlesyndication.com *.doubleclick.net https://www.google.com https://www.google.com.my https://www.google.com.sg https://www.google.co.in https://www.google.co.id https://www.facebook.com/tr/ *.useinsider.com www.maybank.com *.gstatic.com *.googleapis.com http://dbv47yu57n5vf.cloudfront.net https://perfectsencollector.com *.amazonaws.com *.oto.my *.googletagmanager.com *.youtube.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...

Certificates · 7 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
www.maybank2u.com.myMar 20, 2024, 00:00:00Mar 20, 2025, 23:59:59
upload.video.google.comAug 26, 2024, 07:12:45Nov 18, 2024, 07:12:44
*.g.doubleclick.netAug 26, 2024, 06:33:44Nov 18, 2024, 06:33:43
*.google-analytics.comAug 26, 2024, 06:33:47Nov 18, 2024, 06:33:46
*.facebook.comJul 4, 2024, 00:00:00Oct 2, 2024, 23:59:59
livechat.maybank2u.com.myJul 6, 2024, 00:00:00Jul 6, 2025, 23:59:59
www.googleadservices.comAug 26, 2024, 07:12:45Nov 18, 2024, 07:12:44