HTTP Security Headers
sayouth.mobi
Final status: 200
http://sayouth.mobi (308)https://sayouth.mobi/ (302)https://auth.sayouth.mobi/connect/authorize?client_id=4F4133BA-117B-4E4E-932C-CAE6F58E944A&redirect_uri=https%3A%2F%2Fsayouth.mobi%2Fsignin-persistent&response_type=code&scope=openid%20profile&code_challenge=4IbAgkXDDFrN4rfUbK7aEItsN82zf92MCGewMAYa7go&code_challenge_method=S256&response_mode=form_post&nonce=639177948380130275.MGYxNDY0ODAtYmU4NS00MWZjLTgyMjUtYWExMDIzM2QxMGQwMzljYTZmMGQtMjE1Yi00YWZhLTk0ZjAtZTA5YjBkNDhhODAz&txnID=d40fe564-bd30-47b0-8a5c-49e227475b86&prompt=none&state=CfDJ8LUVGe5DlfhMoSCNmJO2OsOyleaX3NuUJPUUevcpBEYvkkdCOgZeJg7bAhkXR_KhBIXmeRR5TzTwPK0B-2Djl4zJQkoOBVlcHD1J3gYTIAwCMx8dBZ8YUdCJmWX8PjJ10vMtwySQQdVmMfI-58IdYAd9TOM8GNnrFbg30cNS_YmG8qof24ZZamgFBXRZW18NBzEmSZegARa2H9lppML_o7yl8WiXoroIJlVdCbM4VA-J6xo2jm6Bjv7vDoslAioKXuJKmUCrgAXoCWlct5MDJ4tnU-gfBMGAK5Cgr9Ieamu070xz3-36nh_jkp8l0RZVrfuBQDLmYsu2R6SPGBa6V0QEmaRbmVDOL8Nqbwunv7Zu8fsJLsk7f73ZwTZCHnuVvw&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 (200)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP)
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy no-referrer
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.