HTTP Security Headers
kinopoisk.ru
Final status: 200
http://kinopoisk.ru (302)http://kinopoisk.ru/showcaptcha?cc=1&form-fb-hint=2.20&mt=574BA7C65C7C9AAFA27FB0831FA4A300ABAE2FA3A2997A3C634E905DF1B698DB36991DD7C17A2118DB323DC1C7BC71C44B41A09DCD2401669377C5AA7CD3B6D373226357C9C14968B79181B02B5022AF1856BF5577E822C90E0DCDCDC09C12628B204D08FB8BD32DC7F49A95865F9FA8E4100D61450E5271FE9C4FD92FF2D442390003599F48B667C89CB3393C7D7F1C94CFD3A3153F35C0C75F2C8A7529B6E1CB98583ED0D7739F72858281769829ACD45454FE066392EDB20C9603FDE0519092C1F837024B219B2402A067D7831F253A292CCE4C4A5AF78154E5146AD5FCF6FF14C34501AD7AAB7A9B50432AAD4C&retpath=aHR0cDovL2tpbm9wb2lzay5ydS8%2C_952431310cc8a58af3db5a95eda1ed17&t=2%252F1782117340%252F0e60299e6b6b1db46f5e409c97783847&u=8915405804071189807&s=0632560671073a9b6ec3c03a4e9eb752 (200)
Security Headers
Strict-Transport-Security (HSTS) — missing
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.