HTTP Security Headers

yad2.co.il

Final status: 200 · Server: Apache
http://yad2.co.il (301)https://yad2.co.il/ (302)https://validate.perfdrive.com/ccb4768f5e2ea98586d13473d71efc83/?ssa=77755379-3a83-45e1-a867-4bbab6562046&ssb=56735359147&ssc=https%3A%2F%2Fyad2.co.il%2F&ssi=8dca6554-bhcz-4e9b-b097-81615ce2b853&ssk=support@shieldsquare.com&ssm=27811955562620508107045981013444&ssn=0a63ea2da7c3bd587021c0cb15f2943b16697ac723ba-f823-4587-963ed9&sso=654319e0-929be2435a2b1948effed56fdfae735f82c6440b135b3d0b&ssp=78100981621783198096178316383306178&ssq=26346059493670505844994936125928502970215&ssr=MzQuMjM4LjIzMi42Nw==&sst=Mozilla/5.0%20(compatible;%20DNS.pizza/1.0;%20+https://dns.pizza)&ssu=&ssv=&ssw=&ssx=eyJyZCI6InlhZDIuY28uaWwiLCJfX3V6bWYiOiI3ZjkwMDA3YWM3MjNiYS1mODIzLTQ1ODctOTllMC05MjliZTI0MzVhMmIxLTE3ODMxOTQ5MzY4OTYwLTAwNDZiOWQxODI2ZTBkNjQ2MzkxMCIsInV6bXgiOiI3ZjkwMDBkMmI1Njk3ZS0yNmU0LTQ4NGQtYTdkYy00Y2I2NDdkNGY1NjQxLTE3ODMxOTQ5MzY4OTYwLTg1MGZjMDYzOWY4ZjA4NjAxMCJ9 (200)

Security Headers

Strict-Transport-Security (HSTS) — missing
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.