https://book.stripe.com/3cs6pZ8wQf3ofiEfYY

Submitted URL:
https://book.stripe.com/3cs6pZ8wQf3ofiEfYY
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 3 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=31556926; includeSubDomains; preloadGood
X-Frame-OptionsGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policybase-uri 'none'; connect-src 'self' https://api.stripe.com https://errors.stripe.com https://js.stripe.com https://r.stripe.com https://checkout-cookies.stripe.com https://stripe.com/cookie-settings/enforcement-mode https://merchant-ui-api.stripe.com; default-src 'self'; font-src 'self' https://js.stripe.com; form-action 'none'; frame-src 'self' https://js.stripe.com https://payments.stripe.com https://checkout.link.com; img-src 'self' https://q.stripe.com https://js.stripe.com https://stripe-camo.global.ssl.fastly.net https://d1wqzb5bdbcre6.cloudfront.net https://qr.stripe.com https://b.stripecdn.com https://files.stripe.com; media-src 'none'; object-src 'none'; script-src 'self' https://js.stripe.com 'sha256-BNulBYV1JXGvq9NQg7814ZyyVZCqfRI1aq5d+PSIdgI=' 'sha256-p9X5vm9nd6f5JCmJL0mA+ivx/NJI3WJP1MlaBO2RDWE=' 'sha256-Rs7zoycEGz8Aoh9NxrpDQaZ9oV27ZjlGKVOcL1V1ntA='; style-src 'self' https://js.stripe.com 'sha256-0wCsuxti3m6dSdXFrCFETD2dpAVJPkB2rNReo7a96ME='; worker-src 'none'; report-uri https://q.stripe.com/csp-reportGood
Referrer-PolicyGood
Clear-Site-DataGood
X-Permitted-Cross-Domain-PoliciesGood
Permissions-PolicyNew
Cross-Origin-Embedder-PolicyNew
Cross-Origin-Opener-PolicyNew
Cross-Origin-Resource-PolicyNew
X-XSS-ProtectionDeprecated
Feature-PolicyDeprecated
Expect-CTDeprecated
Public-Key-PinsDeprecated

Security Violations · 0 found

Requests or resources offending security policies

  • None found

Certificates · 2 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
a.stripecdn.comOct 30, 2024, 00:00:00Feb 6, 2025, 23:59:59
*.stripe.comNov 11, 2024, 00:00:00Feb 27, 2025, 23:59:59