It looks like this is a web page, not a feed. I looked for a feed associated with this page, but couldn't find one. Please enter the address of your feed to validate.


  3. <html lang="en">
  4. <head>
  5. <title>Scan results for</title>
  6. <link rel="icon" type="image/png" href="/images/favicon.ico" />
  7. <meta http-equiv="content-type" content="text/html; charset=utf-8" />
  8. <meta name="description" content="These are the scan results for which scored the grade R." />
  9. <meta name="viewport" content="width=device-width, initial-scale=1">
  10. <meta name="keywords" content="security headers, http response headers, check headers, scan headers" />
  11. <meta name="author" content="Scott Helme" />
  12. <meta property="og:title" content="Scan results for" />
  13. <meta property="og:description" content="These are the scan results for which scored the grade R." />
  14. <meta property="og:url" content="" />
  15. <meta property="og:image" content="" />
  16. <meta property="og:type" content="website" />
  17. <meta property="twitter:card" content="summary" />
  18. <meta property="twitter:title" content="Scan results for" />
  19. <meta property="twitter:description" content="These are the scan results for which scored the grade R." />
  20. <meta property="twitter:site" content="@securityheaders" />
  21. <meta property="twitter:creator" content="@scott_helme" />
  22. <meta property="twitter:img" content="" />
  23. <script src="/js/jquery/3.6.4/jquery.min.js"></script>
  24. <script src="/js/skel/2.2.1/skel.min.js"></script>
  25. <script src="/js/skel-layers/2.0.1/skel-layers.min.js"></script>
  26. <script src="/js/jquery.dropotron.min.js"></script>
  27. <script src="/js/init.min.js?v=1"></script>
  28. <noscript>
  29. <link rel="stylesheet" href="/css/skel/2.2.1/skel.min.css">
  30. </noscript>
  31. <!--[if lte IE 8]><link rel="stylesheet" href="/css/ie/v8.min.css" /><![endif]-->
  32. <link rel="stylesheet" href="/css/style.min.css?v=1.0.19" />
  33. <link rel="stylesheet" media="screen and (min-width: 737px)" href="/css/style-desktop.min.css?v=1.0.17" />
  34. <link rel="stylesheet" media="screen and (min-width: 737px) and (max-width: 1200px)" href="/css/style-1000px.min.css?v=1.0.16" />
  35. <link rel="stylesheet" media="screen and (max-width: 736px)" href="/css/style-mobile.min.css?v=1.0.18" />
  36. <meta name="flattr:id" content="4jvyrv"> </head>
  37. <body class="homepage" id="top">
  38. <div id="header" class="grey">
  39. <div class="container">
  40. <div id="logo">
  41. <h1><a href="/">Security Headers</a></h1>
  42. <h3>Powered by &nbsp;<a href="" target="_blank" rel="noreferrer noopener"><img class="sponsor-image" src="/images/probely_logo_white.png" alt="The logo of our sponsor, Probely."></a></h3>
  43. </div>
  44. <nav id="nav">
  45. <ul>
  46. <li><a href="/">Home</a></li>
  47. <li>
  48. <span>About</span>
  49. <ul>
  50. <li><a href="/about/">Who, Why &amp; How</a></li>
  51. <li><a href="/faq/">FAQ</a></li>
  52. </ul>
  53. </li>
  54. <li>
  55. <span>API</span>
  56. <ul>
  57. <li><a href="/api/">API Keys</a></li>
  58. <li><a href="/api/terms/">Terms</a></li>
  59. <li><a href="/api/docs/">Docs</a></li>
  60. </ul>
  61. </li>
  62. </ul>
  63. </nav> <div id="banner">
  64. <header>
  65. <h2 id="scan-your-site-now">Scan your site now</h2><br/>
  66. <form method="get" action="" name="scan" id="scanForm">
  67. <div>
  68. <div>
  69. <input type="url" name="q" id="q" placeholder="enter address here" autocorrect="off" autocapitalize="off" spellcheck="false" aria-labelledby="scan-your-site-now" value="">
  70. <input class="button big alt" value="Scan" type="submit" id="scan">
  71. </div>
  72. <div>
  73. <input class="checkbox" type="checkbox" name="hide" id="hide"><label for="hide"> Hide results</label>
  74. <input class="checkbox" type="checkbox" name="followRedirects" id="followRedirects">
  75. <label for="followRedirects"> Follow redirects</label>
  76. </div>
  77. </div>
  78. </form>
  79. </header>
  80. </div>
  81. </div>
  82. </div>
  83. <div id="main">
  84. <div class="container">
  85. <div class="row">
  86. <div class="12u">
  87. <div class="reportSection push-top">
  88. <div class="reportTitle">Security Report Summary</div>
  89. <div class="reportBody">
  90. <div class="row">
  91. <div class="2u">
  92. <div class="score">
  93. <div class="score_grey"><span>R</span></div>
  94. </div>
  95. </div>
  96. <div class="10u push-left">
  97. <table class="reportTable">
  98. <col class="col1">
  99. <col class="col2">
  100. <tbody>
  101. <tr class="tableRow">
  102. <th class="tableLabel">Redirect:</th>
  103. <td class="tableCell"><a href=" " rel="nofollow noreferrer noopener">Click here</a> to follow the redirect to</td>
  104. </tr>
  105. <tr class="tableRow">
  106. <th class="tableLabel">Site:</th>
  107. <td class="tableCell">
  108. <a href="" target="_blank" rel="nofollow noreferrer noopener">
  110. - <a href="">(Scan again over https)</a>
  111. </td>
  112. </tr>
  113. <tr class="tableRow">
  114. <th class="tableLabel">IP Address:</th>
  115. <td class="tableCell">
  116. </td>
  117. </tr>
  118. <tr class="tableRow">
  119. <th class="tableLabel">Report Time:</th>
  120. <td class="tableCell">
  121. 20 May 2024 07:39:31 UTC
  122. </td>
  123. </tr>
  124. <tr class="tableRow">
  125. <th class="tableLabel">Headers:</th>
  126. <td class="tableCell">
  127. <ul class="pillList">
  128. <li class="headerItem pill pill-red"><i class="fa fa-times"></i>Content-Security-Policy</li> <li class="headerItem pill pill-red"><i class="fa fa-times"></i>X-Frame-Options</li> <li class="headerItem pill pill-red"><i class="fa fa-times"></i>X-Content-Type-Options</li> <li class="headerItem pill pill-red"><i class="fa fa-times"></i>Referrer-Policy</li> <li class="headerItem pill pill-red"><i class="fa fa-times"></i>Permissions-Policy</li> </ul>
  129. </td>
  130. </tr>
  131. <tr class="tableRow">
  132. <th class="tableLabel">Warning:</th>
  133. <td class="tableCell">
  134. Grade capped at A, please see warnings below. </td>
  135. </tr>
  136. <tr class="tableRow"><th class="tableLabel">Advanced:</th>
  137. <td class="tableCell">
  138. <table><tr><td id="demo-button" width="80%">Perform a deeper security analysis of your website and APIs: </td><td id="demo-button" width="20%"><a href="" target="_blank"><input class="button" value="Start Now" type="submit"></a></td></tr></table> </td></tr>
  139. </tbody>
  140. </table>
  141. </div>
  142. </div>
  143. </div>
  144. </div>
  145. <div class="reportSection">
  146. <div class="reportTitle">Missing Headers</div>
  147. <div class="reportBody">
  148. <table class="reportTable">
  149. <colgroup><col class="col1"><col class="col2"></colgroup>
  150. <tbody>
  151. <tr class="tableRow"><th class="tableLabel table_red">Content-Security-Policy</th><td class="tableCell"><a href="" target="_blank">Content Security Policy</a> is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets.</td></tr><tr class="tableRow"><th class="tableLabel table_red">X-Frame-Options</th><td class="tableCell"><a href="" target="_blank">X-Frame-Options</a> tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. Recommended value "X-Frame-Options: SAMEORIGIN". </td></tr><tr class="tableRow"><th class="tableLabel table_red">X-Content-Type-Options</th><td class="tableCell"><a href="" target="_blank">X-Content-Type-Options</a> stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff".</td></tr><tr class="tableRow"><th class="tableLabel table_red">Referrer-Policy</th><td class="tableCell"><a href="" target="_blank">Referrer Policy</a> is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites.</td></tr><tr class="tableRow"><th class="tableLabel table_red">Permissions-Policy</th><td class="tableCell"><a href="" target="_blank">Permissions Policy</a> is a new header that allows a site to control which features and APIs can be used in the browser.</td></tr> </tbody>
  152. </table>
  153. </div>
  154. </div>
  155. <div class="reportSection">
  156. <div class="reportTitle">Warnings</div>
  157. <div class="reportBody">
  158. <table class="reportTable">
  159. <colgroup><col class="col1"><col class="col2"></colgroup>
  160. <tbody>
  161. <tr class="tableRow"><th class="tableLabel table_orange">Site is using HTTP</th><td class="tableCell">This site was served over HTTP and did not redirect to HTTPS.</td></tr> </tbody>
  162. </table>
  163. </div>
  164. </div>
  165. <div class="reportSection">
  166. <div class="reportTitle">Raw Headers</div>
  167. <div class="reportBody">
  168. <table class="reportTable">
  169. <colgroup>
  170. <col class="col1">
  171. <col class="col2">
  172. </colgroup>
  173. <tbody>
  174. <tr class="tableRow"><th class="tableLabel table_#696E76">HTTP/1.1</th><td class="tableCell">301 Moved Permanently</td></tr><tr class="tableRow"><th class="tableLabel table_blue">Server</th><td class="tableCell">nginx</td></tr><tr class="tableRow"><th class="tableLabel table_#696E76">Date</th><td class="tableCell">Mon, 20 May 2024 07:39:35 GMT</td></tr><tr class="tableRow"><th class="tableLabel table_#696E76">Content-Type</th><td class="tableCell">text/html</td></tr><tr class="tableRow"><th class="tableLabel table_#696E76">Content-Length</th><td class="tableCell">162</td></tr><tr class="tableRow"><th class="tableLabel table_#696E76">Connection</th><td class="tableCell">keep-alive</td></tr><tr class="tableRow"><th class="tableLabel table_#696E76">Location</th><td class="tableCell"></td></tr> </tbody>
  175. </table>
  176. </div>
  177. </div>
  178. <div class="reportSection">
  179. <div class="reportTitle">Upcoming Headers</div>
  180. <div class="reportBody">
  181. <table class="reportTable">
  182. <colgroup><col class="col1"><col class="col2"></colgroup>
  183. <tbody>
  184. <tr class="tableRow"><th class="tableLabel table_blue">Cross-Origin-Embedder-Policy</th><td class="tableCell"><a href="" target="_blank">Cross-Origin Embedder Policy</a> allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP.</td></tr><tr class="tableRow"><th class="tableLabel table_blue">Cross-Origin-Opener-Policy</th><td class="tableCell"><a href="" target="_blank">Cross-Origin Opener Policy</a> allows a site to opt-in to Cross-Origin Isolation in the browser.</td></tr><tr class="tableRow"><th class="tableLabel table_blue">Cross-Origin-Resource-Policy</th><td class="tableCell"><a href="" target="_blank">Cross-Origin Resource Policy</a> allows a resource owner to specify who can load the resource.</td></tr> </tbody>
  185. </table>
  186. </div>
  187. </div>
  188. <div class="reportSection">
  189. <div class="reportTitle">Additional Information</div>
  190. <div class="reportBody">
  191. <table class="reportTable">
  192. <colgroup><col class="col1"><col class="col2"></colgroup>
  193. <tbody>
  194. <tr class="tableRow"><th class="tableLabel table_blue">Server</th><td class="tableCell">This <a href="" target="_blank">Server</a> header seems to advertise the software being run on the server but you can remove or change this value.</td></tr> </tbody>
  195. </table>
  196. </div>
  197. </div>
  198. </div>
  199. </div>
  200. </div>
  201. </div>
  202. <div id="copyright">
  203. <div class="container">
  204. <div class="row">
  205. <div class="4u">
  206. <span>A <a href="" target="_blank"></a> project - <a href="" target="_blank">CC-BY-SA 4.0</a></span>
  207. </div>
  208. <div class="4u" id="sponsor-footer">
  209. <span>Powered by <a href="" target="_blank">Probely</a></span>
  210. </div>
  211. <div class="4u">
  212. <ul class="social">
  213. <li><a href="" class="icon fa-twitter"><span>Twitter</span></a></li>
  214. <li><a href="" class="icon fa-facebook"><span>Facebook</span></a></li>
  215. <li><a href="/cdn-cgi/l/email-protection#c2abaca4ad82b1a7a1b7b0abb6bbaaa7a3a6a7b0b1eca1adaf" class="icon fa-envelope"><span>Email</span></a></li>
  216. </ul>
  217. </div>
  218. </div>
  219. </div>
  220. </div> <script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script><script src="js/scan.js" type="text/javascript"></script>
  221. </body>
  222. </html>
Copyright © 2002-9 Sam Ruby, Mark Pilgrim, Joseph Walton, and Phil Ringnalda