airbnb.com.ee
Grade A · 80/100 · 4/6 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
CSP Analysis
child-src blob:; connect-src 'self' https: wss://ws.airbnb.com wss://ws.airbnb.com.ee https://netverify.com https://*.netverify.com wss: *.amap.com https://*.mapbox.com; default-src 'self' https: blob:; font-src 'self' data: https://*.muscache.com fonts.gstatic.com https://use.typekit.net https:; frame-src * https://*.cardinalcommerce.com; img-src 'self' https: data: https://*.mapbox.com blob:; media-src 'self' https: blob:; script-src 'self' 'unsafe-eval' https://a0.muscache.com https://cdn.siftscience.com https://ss.musthird.com https://t1.musthird.com https://bat.bing.com https://connect.facebook.net https://www.google-analytics.com https://www.googleadservices.com https://tpc.googlesyndication.com https://www.googletagmanager.com https://maps.googleapis.com https://ajax.googleapis.com https://*.g.doubleclick.net https://www.google.com https://www.gstatic.com https://smartlock.google.com https://accounts.google.com https://app.link https://cdn.branch.io https://api.branch.io https://bam.nr-data.net https://js-agent.newrelic.com https://ethn.io https://s.yimg.jp https://api.geetest.com https://monitor.geetest.com https://api.geevisit.com https://cdn.ampproject.org https://storage.googleapis.com/workbox-cdn/ https://tagmanager.google.com https://pay.google.com https://songbird.cardinalcommerce.com/ https://www.recaptcha.net https://www.gstatic.cn https://airbnb-api.arkoselabs.com https://h.online-metrix.net 'sha256-rAm9O8JPZLtQmd84zMDzhsG5q35JscESxxcaFL7+DDc=' 'sha256-Cu2QV7ot69Jkmvhup8U49ZjjsugbAPIITElVNpaE6Eg=' 'sha256-CZnW0hvLQpXhjRl/rvattFn8GcIhxi8fcsCstVugtsI=' 'sha256-QR4frmvqUrh2pELSvwAdRWARdhjOK+jVGVFqid4f1B4=' 'sha256-VB3icgEuK9nxnKeV7ty5UqcBbH/+5mf/84+Z6JUjq+E=' 'sha256-dEQLydru3z2yuRGS/8VzaalU2wY48xuXdoO1zDPmT/A=' 'sha256-XXQFt4Z7kxfkfDRpq3AJfBQnWsjSj4DIh2SgIjdt4tA=' 'sha256-cjbhGOOQgQ99rvg3Z512vKyyYWqlTx/JNJg0rEMcAdY=' 'sha256-GoqTyvhrUGs2a0a9S/yHVXQRfrr7CzXLCRTgpIjb6BM=' 'sha256-HTDMse/MhCOW/p77YF4cvhsDbvhC2YxAFR+l8E4FZvo=' https: https://netverify.com https://*.netverify.com https://icm.aexp-static.com https://qicm.americanexpress.com https://qwww435.americanexpress.com https://checkout.americanexpress.com https://www.paypalobjects.com https://c.paypal.com https://www.paypal.com https://*.klarnacdn.net blob: https://vdata.amap.com https://webapi.amap.com https://restapi.amap.com https://*.mapbox.com https://songbird.cardinalcommerce.com https://songbirdstag.cardinalcommerce.com https://includes.ccdc02.com https://includestest.ccdc02.com https://client-api.arkoselabs.com https://cdn.plaid.com/link/v2/stable/link-initialize.js https://js.stripe.com https://appleid.cdn-apple.com/appleauth/static/jsapi/appleid/1/en_US/appleid.auth.js https://pagead2.googlesyndication.com; style-src 'self' https: 'unsafe-inline' https://*.mapbox.com; worker-src 'self' https: blob:; report-uri /tracking/csp?controller=core-guest-loop&action=%2F&req_uuid=c14f3a9e-f357-41f1-8f4f-af20ef99f66e&version=sha%3D83ab18eb82e6&report_only=false; report-to /tracking/csp?controller=core-guest-loop&action=%2F&req_uuid=c14f3a9e-f357-41f1-8f4f-af20ef99f66e&version=sha%3D83ab18eb82e6&report_only=false
Directive Analysis
Security Headers
Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
How to add it:
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"Rules > Transform Rules > HTTP Response Header Modification > Set Permissions-Policy valueControls how much referrer information is sent with requests, preventing data leaks to third parties.
How to add it:
add_header Referrer-Policy "strict-origin-when-cross-origin" always;Header always set Referrer-Policy "strict-origin-when-cross-origin"Rules > Transform Rules > HTTP Response Header Modification > Set Referrer-Policy to "strict-origin-when-cross-origin"max-age=10886400; includeSubdomains
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
SAMEORIGIN
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
1; mode=block
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
2 recommended security headers are missing on airbnb.com.ee.
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
airbnb.com.ee
3 scans since 7/18/2025
Latest: 80/100
Total Scans
3
Latest Score
80/100
First Scan
7/18/2025
Last Scan
7/18/2025
Score Trend
Security score progression over 2 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/airbnb.com.ee" title="Security headers grade for airbnb.com.ee — HeaderTest">
<img src="https://headertest.com/api/badge/airbnb.com.ee" alt="HeaderTest security grade: A (80/100) for airbnb.com.ee" />
</a>[](https://headertest.com/results/airbnb.com.ee)