Paramètres d'affichage

Choisissez un thème pour personnaliser l'apparence du site.

https://compl-alim.beta.gouv.fr

Vers une circulation de compléments alimentaires conformes à la réglementation, sûrs en termes de santé publique et adaptés aux besoins physiologiques des consommateurs
Copie d'écran de https://compl-alim.beta.gouv.fr

Nmap

Scan Summary :

B

severityservicevulnerability

info

http (port:80)

info

bgp (port:179)

info

https (port:443)

info

socks (port:1080)

info

pvuniwien (port:1081)

info

abyss (port:9999)
Consulter le rapport détaillé

Mozilla HTTP observatory

Scan Summary :

D

ImpactDescriptionDocumentation

-25

Content Security Policy (CSP) header not implemented

-20

Cookies set without using the Secure flag or set over HTTP.

Documentation for cookies-secure-with-httponly-sessions

-20

Strict-Transport-Security header not implemented.

Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/).

Rapport détaillé

SSL

Scan Summary :

A


Grade capped to A. HSTS is not offered


Expiration : 06/08/2025

Rapport détaillé

Scan OWASPenviron 1 heure

riskname

Medium (High)

Content Security Policy (CSP) Header Not Set

Low (High)

Strict-Transport-Security Header Not Set

Low (Medium)

Cookie No HttpOnly Flag

Low (Medium)

Cookie Without Secure Flag

Low (Medium)

Cookie without SameSite Attribute

Low (Medium)

Insufficient Site Isolation Against Spectre Vulnerability

Low (Medium)

Permissions Policy Header Not Set

Low (Medium)

X-Content-Type-Options Header Missing

Informational (High)

Sec-Fetch-Dest Header is Missing

Informational (High)

Sec-Fetch-Mode Header is Missing

Informational (High)

Sec-Fetch-Site Header is Missing

Informational (High)

Sec-Fetch-User Header is Missing

Informational (Medium)

Base64 Disclosure

Informational (Medium)

Modern Web Application

Informational (Medium)

Session Management Response Identified

Informational (Medium)

Storable and Cacheable Content

Informational (Low)

Information Disclosure - Suspicious Comments

Informational (Low)

Re-examine Cache-control Directives

Rapport détaillé

Nuclei21 jours

SéveritéNameMatcher

info

MX Record Detectionmx-fingerprint

info

CAA Recordcaa-fingerprint

info

NS Record Detectionnameserver-fingerprint

info

SPF Record - Detectionspf-record-detect

info

DNS TXT Record Detectedtxt-fingerprint

info

Allowed Options Methodoptions-method

info

HTTP Missing Security Headersstrict-transport-security

info

HTTP Missing Security Headerscontent-security-policy

info

HTTP Missing Security Headerspermissions-policy

info

HTTP Missing Security Headersx-permitted-cross-domain-policies

info

HTTP Missing Security Headersclear-site-data

info

HTTP Missing Security Headerscross-origin-embedder-policy

info

HTTP Missing Security Headerscross-origin-resource-policy

info

robots.txt endpoint proberrobots-txt-endpoint

info

robots.txt filerobots-txt

info

WAF Detectionapachegeneric

info

Detect SSL Certificate Issuerssl-issuer

info

SSL DNS Namesssl-dns-names

info

TLS Version - Detecttls-version

info

TLS Version - Detecttls-version