HTTP Security Headers
yastatic.net
Final status: 200
http://yastatic.net (302)https://api.yandex.ru/jslibs (301)https://yandex.ru/dev/jslibs (302)https://yandex.ru/showcaptcha?cc=1&form-fb-hint=2.74&mt=6A344C78931124191E3DCB1A93DDDD61ADC113DB8318714E6E6BBC15FC3143FD406F6F802B0F871BC6AC0C1233EFC5110BD1BC17B5B4BC48D5E84E407BAF65B22162C2B5D72204DA64092240B4494464A2E4D8C890DAD9C8E535C71B2DE7A62A7E87DF972C7C6F4C9CD24C88440594AB8329148E80312DCB3250C280951DFF5C8753E94783F229CCC5A3A45D102E7FD8DEF9202DE5232C2C47952B95E5D6017024BF5EFC8B95D3F3C22CC754600064DC15869BA8EC610AB74F3B3640DB39CD30B99AA51A25C37FD0E2EF8C7D096B87A163EA787BA1BE8653C9A7AC9CE0E3A3A1B467087A1C257A5EF55A1917C558F9EFF5F8&retpath=aHR0cHM6Ly95YW5kZXgucnUvZGV2L2pzbGlicw%2C%2C_121986d9ab82090274f68dd2572c2782&t=2%252F1782103848%252F8c15f0cfbc989a3555be99716b21f424&u=8914500349130347060&s=fd1b642e8fef7ee358be28c9f48eb141 (200)
Security Headers
Strict-Transport-Security (HSTS) — missing
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.