HTTP Security Headers
myisolved.com
Final status: 200 · Server: cloudflare · X-Powered-By: ASP.NET
http://myisolved.com (302)https://myisolved.com/ (302)https://myisolved.com/UserLogin.aspx?ReturnUrl=%2f (302)https://identity.myisolved.com/connect/authorize?client_id=isolved-infin&response_type=code&scope=openid%20offline_access%20core-api%20notifications-api%20analytics-hub-api%20reporting-hub-api%20print-utility-api%20perfect-payroll-api%20tax-mfe-api%20fraud-protection-api%20adaptive-perform-api&code_challenge=gZiTawTAVHvJUQN6n3DhJ7XBihux_N8ruVG0oOXyRJU&code_challenge_method=S256&state=X-Z8yVkmh7RZMVqx1JhI966gTbjzzDaq0ktusd2cFJUdYzvC6DnAxlv0V8LPs87gJrHhEsLh8K2w0Cpgk9dyuk2e_b7TG14rmMsDs659k3QC7fVzuo914QRUAz9ZoQwhRqJewcy5PBWOBqiZZx-tRbUGo8uX58Zn43BhnqzbTcA&nonce=639197997173072438.YTgzZTJkZDQtNDY1Mi00MzUwLWFmZTAtNWIyZDYyZjUwZWFiNzRlZTQwYmQtYWNlMi00MjQ0LWExYzEtMjBlNTNhMjBjNTc1&redirect_uri=https%3A%2F%2Fmyisolved.com%2Fsignin-oidc (302)https://identity.myisolved.com/Account/Login?ReturnUrl=%2Fconnect%2Fauthorize%2Fcallback%3Fclient_id%3Disolved-infin%26response_type%3Dcode%26scope%3Dopenid%2520offline_access%2520core-api%2520notifications-api%2520analytics-hub-api%2520reporting-hub-api%2520print-utility-api%2520perfect-payroll-api%2520tax-mfe-api%2520fraud-protection-api%2520adaptive-perform-api%26code_challenge%3DgZiTawTAVHvJUQN6n3DhJ7XBihux_N8ruVG0oOXyRJU%26code_challenge_method%3DS256%26state%3DX-Z8yVkmh7RZMVqx1JhI966gTbjzzDaq0ktusd2cFJUdYzvC6DnAxlv0V8LPs87gJrHhEsLh8K2w0Cpgk9dyuk2e_b7TG14rmMsDs659k3QC7fVzuo914QRUAz9ZoQwhRqJewcy5PBWOBqiZZx-tRbUGo8uX58Zn43BhnqzbTcA%26nonce%3D639197997173072438.YTgzZTJkZDQtNDY1Mi00MzUwLWFmZTAtNWIyZDYyZjUwZWFiNzRlZTQwYmQtYWNlMi00MjQ0LWExYzEtMjBlNTNhMjBjNTc1%26redirect_uri%3Dhttps%253A%252F%252Fmyisolved.com%252Fsignin-oidc (200)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP)
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options SAMEORIGIN
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy same-origin
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.