https://gitlab.xisumavoid.com/users/sign_in

Submitted URL:
https://gitlab.xisumavoid.com/Redirected
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 8 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=315360000; includeSubDomains; preloadGood
X-Frame-OptionsSAMEORIGINGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policyconnect-src 'self' http://localhost:* ws://localhost:* wss://localhost:* https://cdn.cookielaw.org https://*.onetrust.com; default-src 'self'; frame-ancestors 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://content.googleapis.com https://content-compute.googleapis.com https://content-cloudbilling.googleapis.com https://content-cloudresourcemanager.googleapis.com; img-src * data: blob:; object-src 'none'; script-src 'self' 'unsafe-eval' http://localhost:* https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.gstatic.com/recaptcha/ https://apis.google.com https://cdn.cookielaw.org https://*.onetrust.com https://cdn.bizible.com/scripts/bizible.js 'nonce-ukK5glLWmByDea2P+k83Ew=='; style-src 'self' 'unsafe-inline'; worker-src 'self' blob:Good
Referrer-Policystrict-origin-when-cross-originGood
Clear-Site-DataGood
X-Permitted-Cross-Domain-PoliciesnoneGood
Permissions-Policyinterest-cohort=()New
Cross-Origin-Embedder-PolicyNew
Cross-Origin-Opener-PolicyNew
Cross-Origin-Resource-PolicyNew
X-XSS-Protection1; mode=blockDeprecated
Feature-PolicyDeprecated
Expect-CTDeprecated
Public-Key-PinsDeprecated

Security Violations · 0 found

Requests or resources offending security policies

  • None found

Certificates · 1 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
gitlab.xisumavoid.comNov 28, 2024, 20:21:08Feb 26, 2025, 20:21:07