@@ -15,92 +15,108 @@ tags: headers
15
15
16
16
<!-- markdown-link-check-disable -->
17
17
18
- ⏲️ Last update: 02/02/2025 at 08:26:37 - Domains analyzed count: 150000.
18
+
19
+
20
+ ⏲️ Last update: 02/02/2025 at 15:29:30 - Domains analyzed count: 150000.
19
21
20
22
## Global usage of secure headers
21
23
22
24
Provide the distribution of usage of secure headers across all domains analyzed.
23
25
24
26
![ be611e71c615c27471d766612bfb7e8b05d743c7] ( assets/tab_stats_generated_images/be611e71c615c27471d766612bfb7e8b05d743c7.png )
25
27
28
+
26
29
## Global usage of header 'Cache-Control'
27
30
28
31
Provide the distribution of usage of the header 'Cache-Control' across all domains analyzed.
29
32
30
33
![ 5b54b09f5f5c815a014d71b3b07495a69e3a4509] ( assets/tab_stats_generated_images/5b54b09f5f5c815a014d71b3b07495a69e3a4509.png )
31
34
35
+
32
36
## Global usage of header 'Clear-Site-Data'
33
37
34
38
Provide the distribution of usage of the header 'Clear-Site-Data' across all domains analyzed.
35
39
36
40
![ 2e12376a6c60ad301b25193c11517ea0cd6aba2f] ( assets/tab_stats_generated_images/2e12376a6c60ad301b25193c11517ea0cd6aba2f.png )
37
41
42
+
38
43
## Global usage of header 'Content-Security-Policy'
39
44
40
45
Provide the distribution of usage of the header 'Content-Security-Policy' across all domains analyzed.
41
46
42
47
![ 5e74150e7d98f861bf3fa632ca32e2d7f3e59632] ( assets/tab_stats_generated_images/5e74150e7d98f861bf3fa632ca32e2d7f3e59632.png )
43
48
49
+
44
50
## Global usage of header 'Cross-Origin-Embedder-Policy'
45
51
46
52
Provide the distribution of usage of the header 'Cross-Origin-Embedder-Policy' across all domains analyzed.
47
53
48
54
![ 00334f25a22543fb684dbe10861afee71c5263e0] ( assets/tab_stats_generated_images/00334f25a22543fb684dbe10861afee71c5263e0.png )
49
55
56
+
50
57
## Global usage of header 'Cross-Origin-Opener-Policy'
51
58
52
59
Provide the distribution of usage of the header 'Cross-Origin-Opener-Policy' across all domains analyzed.
53
60
54
61
![ f700c02d30083cf617bdeca51e7eec3d49fe4a08] ( assets/tab_stats_generated_images/f700c02d30083cf617bdeca51e7eec3d49fe4a08.png )
55
62
63
+
56
64
## Global usage of header 'Cross-Origin-Resource-Policy'
57
65
58
66
Provide the distribution of usage of the header 'Cross-Origin-Resource-Policy' across all domains analyzed.
59
67
60
68
![ fa069b07281496f391d957d8936337da1a601614] ( assets/tab_stats_generated_images/fa069b07281496f391d957d8936337da1a601614.png )
61
69
70
+
62
71
## Global usage of header 'Permissions-Policy'
63
72
64
73
Provide the distribution of usage of the header 'Permissions-Policy' across all domains analyzed.
65
74
66
75
![ 0792b92709f42a7962c27c64b74b94a4dfbffda1] ( assets/tab_stats_generated_images/0792b92709f42a7962c27c64b74b94a4dfbffda1.png )
67
76
77
+
68
78
## Global usage of header 'Referrer-Policy'
69
79
70
80
Provide the distribution of usage of the header 'Referrer-Policy' across all domains analyzed.
71
81
72
82
![ d5e855464d800d7b27eb3e430c5ae378497ddf50] ( assets/tab_stats_generated_images/d5e855464d800d7b27eb3e430c5ae378497ddf50.png )
73
83
84
+
74
85
## Global usage of header 'Strict-Transport-Security'
75
86
76
87
Provide the distribution of usage of the header 'Strict-Transport-Security' across all domains analyzed.
77
88
78
89
![ dbeb94ebb1ed7763f390b7be97a292f3c66920c7] ( assets/tab_stats_generated_images/dbeb94ebb1ed7763f390b7be97a292f3c66920c7.png )
79
90
91
+
80
92
## Global usage of header 'X-Content-Type-Options'
81
93
82
94
Provide the distribution of usage of the header 'X-Content-Type-Options' across all domains analyzed.
83
95
84
96
![ 0259a15512c639e10df724dc019babf03534b303] ( assets/tab_stats_generated_images/0259a15512c639e10df724dc019babf03534b303.png )
85
97
98
+
86
99
## Global usage of header 'X-Frame-Options'
87
100
88
101
Provide the distribution of usage of the header 'X-Frame-Options' across all domains analyzed.
89
102
90
103
![ 6ddd8e89eb34224bf460f672999c7dd447baef79] ( assets/tab_stats_generated_images/6ddd8e89eb34224bf460f672999c7dd447baef79.png )
91
104
105
+
92
106
## Global usage of header 'X-Permitted-Cross-Domain-Policies'
93
107
94
108
Provide the distribution of usage of the header 'X-Permitted-Cross-Domain-Policies' across all domains analyzed.
95
109
96
110
![ 364a633adcd63d315ec3df781fed6008c57ad00d] ( assets/tab_stats_generated_images/364a633adcd63d315ec3df781fed6008c57ad00d.png )
97
111
112
+
98
113
## Global usage of insecure framing configuration via the header 'x-frame-options'
99
114
100
115
Provide the distribution of usage of the header 'x-frame-options' across all domains analyzed with a insecure framing configuration: value different from ` DENY ` or ` SAMEORIGIN ` including unsupported values.
101
116
102
117
![ ccc438a754b6d9324c9c1ea62662969c6114bfdf] ( assets/tab_stats_generated_images/ccc438a754b6d9324c9c1ea62662969c6114bfdf.png )
103
118
119
+
104
120
## Global usage of insecure referrer configuration via the header 'referrer-policy'
105
121
106
122
Provide the distribution of usage of the header 'referrer-policy' across all domains analyzed with a insecure referrer configuration: value set to ` unsafe-url ` or ` no-referrer-when-downgrade ` .
@@ -109,18 +125,21 @@ Provide the distribution of usage of the header 'referrer-policy' across all dom
109
125
110
126
![ e90a8350bb77972b086599b65efc8fcd02036a11] ( assets/tab_stats_generated_images/e90a8350bb77972b086599b65efc8fcd02036a11.png )
111
127
128
+
112
129
## Global usage of the Strict Transport Security 'preload' feature
113
130
114
131
Provide the distribution of usage of the '[ preload] ( https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security#preloading_strict_transport_security ) ' feature for the header 'strict-transport-security' across all domains analyzed.
115
132
116
133
![ 8dd898e970a4cc540e0394ace9c9cedd425bc1c5] ( assets/tab_stats_generated_images/8dd898e970a4cc540e0394ace9c9cedd425bc1c5.png )
117
134
135
+
118
136
## Global common 'max-age' values of the Strict Transport Security header
119
137
120
138
* Most common value used is 31536000 seconds (525600 minutes) across all domains analyzed.
121
139
* Maximum value used is 1234513412313 seconds (20575223539 minutes) across all domains analyzed.
122
140
* Minimum value used is -5375190 seconds (-89586 minutes) across all domains analyzed.
123
141
142
+
124
143
## Global usage of content security policy with directives allowing unsafe expressions
125
144
126
145
Provide the distribution of content security policy allowing unsafe expressions across all domains analyzed.
@@ -130,3 +149,4 @@ Determine if a CSP policy contains `(default-src|script-src|script-src-elem|scri
130
149
Based on [ Report-URI CSP] ( https://report-uri.com/home/generate ) generator allowed instructions for CSP directives.
131
150
132
151
![ c7ef83055cf836a48ed9dd26b3a8d55103645022] ( assets/tab_stats_generated_images/c7ef83055cf836a48ed9dd26b3a8d55103645022.png )
152
+
0 commit comments