HTTP Security Headers

uzum.uz

Final status: 200 · Server: ycalb
http://uzum.uz (301)https://uzum.uz/ (302)https://uzum.uz/tmgrdfrend/showcaptcha?cc=1&form-fb-hint=1.150&mt=402180CF35C584F7307A1A6CA85629B2156E42F67C0228CB23478E97E7AF5DBD7C679A5820DB57F4644098732947A79B97A24979E30FCAEC0A873D5B9183D45847758BC5096CF4F94EE926FF38EAC80FE605837D5BD2B3B6818B3AAE930DD90FA1A45FA7A3011199C3F4FD49BF13CDF26AD12CA8CDE04EB41AED47F2364C1FCA85C81F923A41FF40EBD4AE22F1A126BFFFE47E85E1FDC331BCB17C49F759E54EA84C08FFD4434E84A85E665A6090F4A68083C7282F61709B1FA967F348DE19981CFC4AD1CD42DA7142E1BBDFB0225D59949BFD3009698FAAD936D2DD70F10D0B65DD2CBDA13D136EF8958CA64509A019B762&retpath=aHR0cHM6Ly91enVtLnV6Lw%2C%2C_d74391495ac55a588e4d022391166da0&t=7%252F1783305613%252F0547be44a0e262ccc2fc7006a011fca7&u=8995149440795279986&s=adb0cdaf3c9b26d256e149a76efdb47c (200)

Security Headers

Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.