https://www.iiss.org/

提交的 URL:
https://www.iiss.org/
报告完成时间:

风险 · 找到 0 个

可能带来安全风险的做法

  • 无分类

安全标头 · 找到 5 个

可以增强 Web 应用程序安全性的 HTTP 响应标头

名称支持信息
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preload良性
X-Frame-OptionsSAMEORIGIN良性
X-Content-Type-Optionsnosniff良性
Content-Security-Policydefault-src 'self' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; style-src 'self' 'unsafe-inline' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; font-src 'self' 'unsafe-inline' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; img-src * 'self' data: data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; connect-src 'self' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com; frame-src 'self' *; object-src 'self' *; 良性
Referrer-Policy良性
Clear-Site-Data良性
X-Permitted-Cross-Domain-Policies良性
Permissions-Policygeolocation=(self)
Cross-Origin-Embedder-Policy
Cross-Origin-Opener-Policy
Cross-Origin-Resource-Policy
X-XSS-Protection停用
Feature-Policy停用
Expect-CT停用
Public-Key-Pins停用

安全违规行为 · 找到 1 个

违反安全策略的请求或资源

违规类型信息
资源
https://www.iiss.org/
描述
Refused to load the script 'https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: mediastream: blob: filesystem: ws: wss: aptrinsic.com azure.com cloudflare.com cloudfront.net doubleclick.net episerver.com episerver.net facebook.com facebook.net fb.me fbcdn.net flickr.com google-analytics.com google.com googleapis.com googletagmanager.com gstatic.com iissjournal.org jsdelivr.net licdn.com linkedin.com maptiler.com maxcdn.com oribi.io sagepay.com staticflickr.com twitter.com twimg.com unpkg.com visualstudio.com windows.net youtube.com *.aptrinsic.com *.azure.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.episerver.com *.episerver.net *.facebook.com *.facebook.net *.fb.me *.fbcdn.net *.flickr.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.iissjournal.org *.jsdelivr.net *.licdn.com *.linkedin.com *.maptiler.com *.maxcdn.com *.oribi.io *.sagepay.com *.staticflickr.com *.twitter.com *.twimg.com *.unpkg.com *.visualstudio.com *.windows.net *.youtube.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
内容安全策略

证书 · 找到· 12 个

SSL/TLS 证书使网站能够加密客户端和服务器之间的事务并提供服务器身份验证

主题颁发日期到期日期
www.iiss.org2024年11月8日 04:53:522025年2月6日 04:53:51
upload.video.google.com2024年10月21日 08:38:002025年1月13日 08:37:59
cdnjs.cloudflare.com2024年11月26日 07:25:182025年2月24日 07:25:17
www.google.com2024年10月21日 08:38:452025年1月13日 08:38:44
live.sagepay.com2024年5月29日 18:42:472025年6月22日 18:42:46
*.google-analytics.com2024年10月21日 08:36:572025年1月13日 08:36:56
*.gstatic.com2024年10月21日 08:37:592025年1月13日 08:37:58
snap.licdn.com2024年12月2日 00:00:002025年12月1日 23:59:59
js.monitor.azure.com2024年11月19日 03:45:332025年5月18日 03:45:33
*.google.com2024年10月21日 08:36:572025年1月13日 08:36:56