https://mymediads.com/sabubukna/

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 5 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Security—Good
X-Frame-OptionsSAMEORIGIN SAMEORIGINGood
X-Content-Type-Optionsnosniff nosniffGood
Content-Security-Policyupgrade-insecure-requests; default-src * data: 'unsafe-eval' 'unsafe-inline'Good
Referrer-Policyno-referrer-when-downgradeGood
Clear-Site-Data—Good
X-Permitted-Cross-Domain-Policies—Good
Permissions-Policy—New
Cross-Origin-Embedder-Policy—New
Cross-Origin-Opener-Policy—New
Cross-Origin-Resource-Policy—New
X-XSS-Protection1; mode=block; mode=blockDeprecated
Feature-Policy—Deprecated
Expect-CT—Deprecated
Public-Key-Pins—Deprecated

Security Violations · 1 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://mymediads.com/sabubukna/
Description
Refused to create a worker from 'blob:https://mymediads.com/77585848-22c3-470c-8605-21a5401f009e' because it violates the following Content Security Policy directive: "default-src * data: 'unsafe-eval' 'unsafe-inline'". Note that 'worker-src' was not explicitly set, so 'default-src' is used as a fallback. Note that '*' matches only URLs with network schemes ('http', 'https', 'ws', 'wss'), or URLs whose scheme matches `self`'s scheme. The scheme 'blob:' must be added explicitly.
Content Security Policy

Certificates · 9 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
mymediads.comOct 10, 2024, 19:57:53Oct 10, 2025, 19:57:53
cdnjs.cloudflare.comSep 28, 2024, 05:35:05Dec 27, 2024, 05:35:04
use.fontawesome.comNov 7, 2024, 23:24:31Feb 6, 2025, 00:24:26
upload.video.google.comOct 21, 2024, 08:38:00Jan 13, 2025, 08:37:59
*.googleusercontent.comOct 21, 2024, 08:37:53Jan 13, 2025, 08:37:52
*.google-analytics.comOct 21, 2024, 08:36:57Jan 13, 2025, 08:36:56
*.api.oneall.comAug 2, 2024, 00:00:00Aug 2, 2025, 23:59:59
*.gstatic.comOct 21, 2024, 08:37:59Jan 13, 2025, 08:37:58
pixiv.netNov 11, 2024, 06:38:42Feb 9, 2025, 07:38:39