Security Audit
www.alexa.com
Hosted at 99.84.222.72
View Results Email Report Scan a different site Scan a different site86/100
Astra Health ScoreSecurity Audit Results
We detected suboptimal or unsafe practices on your website. Please see the list below for more details.
-
X-Frame-Options (XFO) header cannot be recognized Header Security High
Description:Our scanners were not able to recognize the X-Frame-Options header..
Remediation:Follow this guide to fix this, find the guide here.
-
Content Security Policy (CSP) header not implemented Header Security Low
Description:Our scanners were not able to detect Content Security Policy (CSP) header amongst the header returned by your site..
Remediation:Follow this guide to fix this, find the guide here.
-
Cookies set without using the Secure flag, but transmission over HTTP prevented by HSTS Cookie Security Low
Description:Cookies are often used in applications to identify and authenticate a user, so stealing a cookie can lead to hijacking of the authenticated user's session. Cookies on your site are set without using the Secure flag, but transmission over HTTP is prevented as HSTS is enabled on your site. Current implementation is not vulnerable but you should consider using Secure Flag on cookies whenever possible..
Remediation:Follow this guide to fix this, find the guide here.