HTTP Security Headers

etimad.sa

Final status: 200
http://etimad.sa (302)https://etimad.sa/ (302)https://portal.etimad.sa/ (302)https://login.etimad.sa/connect/authorize?client_id=3d0e0866a0ac4c568f1856d1d4673fb9&redirect_uri=https%3A%2F%2Fportal.etimad.sa&response_mode=form_post&response_type=code%20id_token%20token&scope=openid%20profile%20roles&state=OpenIdConnect.AuthenticationProperties%3DFPxEAWHO0P6YU2UK4Um49Z3qaZLaFvGxZ1yjO-m5w89wTc35j4iI92RYW_nwSE38pvyMos3xtwR6g85aLL1X8Lv5hm-ubAi1GwCiVCWB8ESCAz8reKLXzsDrgtChrV7mKGALdgcsp8ycwD0yAXAyv8046D7boNkoaCs5AGDWu2wF2yvmUGshQrMkzUIFRF6LhAFu7q7yxWaxEQXI1dAj3A&nonce=639202266935897425.YjliZTI2ZDctM2QwNS00MGM0LWE1ODktOGM3MWYyOGViNzA2N2E3NmMwODItYTVkYy00NmJjLWEyNjUtMDMyZGMyNGI2Njc2&prompt=none&x-client-SKU=ID_NET472&x-client-ver=6.24.0.0 (200)

Security Headers

Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP)
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy no-referrer
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.