SECURITYHEADERS.IO 网站分析
访问网站 securityheaders.io 时发生错误
我们在尝试访问网站 securityheaders.io 的以下 URL 地址时遇到错误:
- HTTP 403 http://securityheaders.io/
- HTTP 403 https://securityheaders.io/
HTTP 403 是一个 HTTP 状态码,表示禁止访问请求的资源。当服务器限制我们的机器人访问页面时,就会发生这种情况,通常是由于防火墙的存在。
以下内容展示了我们服务器在 2024-09-30 缓存的部分历史分析数据。由于我们的机器人无法访问此网站,数据可能不完整或已过时,仅供您参考。
基本信息
服务器:
cloudflare
IP:
城市:
页面信息
标题:
Analyse your HTTP response headers
长度: 34 字符; 最佳长度: 10 ~ 60 字符
Meta 描述信息:
Quickly and easily assess the security of your HTTP response headers
长度: 68 字符; 最佳长度: 50 ~ 160 字符
Meta 关键词:
security headers, http response headers, check headers, scan headers
长度: 68 字符; 最佳长度: 10 ~ 255 字符
H1标签:
Security Headers
长度: 16 字符; 最佳长度: 10 ~ 255 字符
外部链接:
6 (0 nofollow)
内部链接:
26 (0 nofollow)
建站技术
服务器:
cloudflare
SSL 安全:
有效
robots.txt:
不可用
XML 站点地图:
不可用
Gzip 压缩:
有效
favicon.ico:
不可用
HTTP Head 分析
HTTP 协议采用了请求与响应模型,通过 HTTP Header 定义了 HTTP 传输过程中的必要参数。 浏览器(例如 Internet Explorer, Google Chrome, Firefox 等)并不会显示 HTTP header 字段的内容,下面是网站 securityheaders.io 的 HTTP header 信息:
HTTP/1.1 200 OK
Date: Tue, 01 Oct 2024 01:29:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
set-cookie: anti_forgery_cookie=2889fd2f13a4369b2005fb74a1087030; expires=Tue, 01-Oct-2024 03:29:36 GMT; Max-Age=7200; path=/
access-control-allow-origin: *
content-security-policy: default-src 'self'; script-src 'self' js.stripe.com static.cloudflareinsights.com www.google.com/recaptcha/api.js www.gstatic.com/recaptcha/releases/; img-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com; form-action 'self'; frame-src js.stripe.com www.google.com; report-uri https://scotthelme.report-uri.com/r/d/csp/enforce; report-to default
strict-transport-security: max-age=31536000; includeSubDomains; preload
referrer-policy: strict-origin-when-cross-origin
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block; report=https://scotthelme.report-uri.com/r/d/xss/enforce
x-content-type-options: nosniff
expect-ct: max-age=0, report-uri="https://scotthelme.report-uri.com/r/d/ct/reportOnly"
permissions-policy: accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
report-to: {"group":"default","max_age":31536000,"endpoints":[{"url":"https://scotthelme.report-uri.com/a/d/g"}],"include_subdomains":true}
nel: {"report_to":"default","max_age":31536000,"include_subdomains":true}
Cache-Control: public, max-age=60
cross-origin-embedder-policy-report-only: require-corp; report-to="default"
cross-origin-opener-policy-report-only: same-origin; report-to="default"
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 8cb8aec37c99429e-EWR
Content-Encoding: gzip
Date: Tue, 01 Oct 2024 01:29:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
set-cookie: anti_forgery_cookie=2889fd2f13a4369b2005fb74a1087030; expires=Tue, 01-Oct-2024 03:29:36 GMT; Max-Age=7200; path=/
access-control-allow-origin: *
content-security-policy: default-src 'self'; script-src 'self' js.stripe.com static.cloudflareinsights.com www.google.com/recaptcha/api.js www.gstatic.com/recaptcha/releases/; img-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com; form-action 'self'; frame-src js.stripe.com www.google.com; report-uri https://scotthelme.report-uri.com/r/d/csp/enforce; report-to default
strict-transport-security: max-age=31536000; includeSubDomains; preload
referrer-policy: strict-origin-when-cross-origin
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block; report=https://scotthelme.report-uri.com/r/d/xss/enforce
x-content-type-options: nosniff
expect-ct: max-age=0, report-uri="https://scotthelme.report-uri.com/r/d/ct/reportOnly"
permissions-policy: accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
report-to: {"group":"default","max_age":31536000,"endpoints":[{"url":"https://scotthelme.report-uri.com/a/d/g"}],"include_subdomains":true}
nel: {"report_to":"default","max_age":31536000,"include_subdomains":true}
Cache-Control: public, max-age=60
cross-origin-embedder-policy-report-only: require-corp; report-to="default"
cross-origin-opener-policy-report-only: same-origin; report-to="default"
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 8cb8aec37c99429e-EWR
Content-Encoding: gzip
DNS 记录分析
DNS 域名系统(Domain Name System,缩写)是 Internet 的一项基础服务。它作为将域名和IP地址相互映射的一个分布式数据库,能够使人更方便地访问互联网。securityheaders.io 当前共有 13 项 DNS 记录。
| 主机 | 类型 | IP/目标 | 生存时间 | 扩充信息 |
|---|---|---|---|---|
| securityheaders.io | A | 296 | ||
| securityheaders.io | A | 296 | ||
| securityheaders.io | NS | 21600 | ||
| securityheaders.io | NS | 21600 | ||
| securityheaders.io | SOA | 1800 | expire: 604800 serial: 2351537871 | |
| securityheaders.io | MX | 300 | pri: 10 | |
| securityheaders.io | MX | 300 | pri: 20 | |
| securityheaders.io | TXT | v=spf1 include:spf.messagingengine.com -all | 300 | |
| securityheaders.io | TXT | google-site-verification=Ope15tGgC-fqidRzJOi3pJfLYAUjg-fC1BzWgKHciJY | 300 | |
| securityheaders.io | TXT | keybase-site-verification=36kRxygqDNby_83957VhO1OKAkrU-JQeY1apzZL3HTE | 300 | |
| securityheaders.io | TXT | blitz=mu-d15e2e49-bd72d4fd-b5efada7-c5904cb1 | 300 | |
| securityheaders.io | AAAA | 2606:4700:3031::ac43:c46b | 300 | |
| securityheaders.io | AAAA | 2606:4700:3033::6815:1532 | 300 |