← All Results
Domain History

amservmotors.lv

Grade A · 80/100 · 4/6 security headers present

Security Score

A
80/ 100

Security Headers

4/ 6

CSP Violations

NoViolations

Issues Found

0Issues

Recommendations

0Available

CSP Analysis

Content Security PolicyHIGH
default-src 'self' ; connect-src 'self' wss: * ; font-src 'self' fonts.gstatic.com use.fontawesome.com webshop.abahn.net ccchat.estpak.ee embed.tawk.to data: ; img-src blob: data: http: https: 'self' ; script-src 'self' cdn.modera.org *.salesfront.eu modera-serverless-microservices-assets.s3.eu-north-1.amazonaws.com www.google-analytics.com ssl.google-analytics.com www.googletagmanager.com www.googleadservices.com googleads.g.doubleclick.net www.google.com www.youtube.com www.gstatic.com connect.facebook.net consent.cookiebot.com consentcdn.cookiebot.com static.zdassets.com cdnjs.cloudflare.com cdn.jsdelivr.net code.jquery.com ajax.googleapis.com maps.googleapis.com maps.google.com webshop.abahn.net banners.adnetmedia.lt mediabrands.containers.piwik.pro services.digitalmatter.ai scdn.cxense.com id.cxense.com track.adform.net s2.adform.net static.hotjar.com script.hotjar.com cdn.visitor.chat ccchat.estpak.ee snap.licdn.com cdn-cookieyes.com analytics.tiktok.com pagead2.googlesyndication.com embed.tawk.to plausible.io www.redditstatic.com delfilt.adocean.pl chat.askly.me 'unsafe-inline' 'unsafe-eval' ; style-src data: 'self' cdn.modera.org *.salesfront.eu fonts.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net webshop.abahn.net use.fontawesome.com ccchat.estpak.ee embed.tawk.to 'unsafe-inline' ; media-src http: https: 'self' ; base-uri chat.askly.me 'self' ; object-src 'none' ; frame-src http: https: 'self'; upgrade-insecure-requests ; block-all-mixed-content;
Directive Analysis
default-srcLOW
'self'
•Missing recommended values for default-src: self
connect-srcHIGH
wss: 'self' *
•Overly permissive wildcard (*) in connect-src
•Missing recommended values for connect-src: self
font-srcLOW
use.fontawesome.com ccchat.estpak.ee embed.tawk.to webshop.abahn.net data: 'self' fonts.gstatic.com
•Missing recommended values for font-src: self
img-srcMEDIUM
https: http: blob: data: 'self'
•Insecure HTTP source allowed in img-src
•Missing recommended values for img-src: self
script-srcHIGH
delfilt.adocean.pl 'unsafe-inline' cdn.visitor.chat id.cxense.com services.digitalmatter.ai cdn-cookieyes.com maps.google.com track.adform.net s2.adform.net analytics.tiktok.com www.google.com www.youtube.com consent.cookiebot.com www.google-analytics.com ssl.google-analytics.com ccchat.estpak.ee plausible.io static.hotjar.com chat.askly.me script.hotjar.com static.zdassets.com scdn.cxense.com maps.googleapis.com 'unsafe-eval' cdnjs.cloudflare.com www.redditstatic.com consentcdn.cookiebot.com mediabrands.containers.piwik.pro embed.tawk.to banners.adnetmedia.lt modera-serverless-microservices-assets.s3.eu-north-1.amazonaws.com *.salesfront.eu cdn.modera.org snap.licdn.com webshop.abahn.net cdn.jsdelivr.net 'self' ajax.googleapis.com googleads.g.doubleclick.net www.gstatic.com code.jquery.com www.googletagmanager.com connect.facebook.net www.googleadservices.com pagead2.googlesyndication.com
•Unsafe inline execution allowed in script-src
•Unsafe eval() execution allowed in script-src
•Missing recommended values for script-src: sha512-, self, sha256-, nonce-, sha384-
•No nonces or hashes used for script-src
style-srcHIGH
cdnjs.cloudflare.com use.fontawesome.com ccchat.estpak.ee embed.tawk.to 'unsafe-inline' *.salesfront.eu cdn.modera.org webshop.abahn.net cdn.jsdelivr.net data: 'self' fonts.googleapis.com
•Unsafe inline execution allowed in style-src
•Missing recommended values for style-src: sha512-, self, sha256-, nonce-, sha384-
media-srcMEDIUM
https: 'self' http:
•Insecure HTTP source allowed in media-src
•Missing recommended values for media-src: self
base-uriLOW
'self' chat.askly.me
•Missing recommended values for base-uri: self, none
object-srcLOW
'none'
•Missing recommended values for object-src: none
frame-srcMEDIUM
https: 'self' http:
•Insecure HTTP source allowed in frame-src
•Missing recommended values for frame-src: self
upgrade-insecure-requestsLOW
block-all-mixed-contentLOW

Security Headers

✗Permissions-PolicyMissing

Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.

How to add it:

nginx
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
apache
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
cloudflare
Rules > Transform Rules > HTTP Response Header Modification > Set Permissions-Policy value
✓Referrer-PolicyPresent

no-referrer, strict-origin-when-cross-origin

Controls how much referrer information is sent with requests, preventing data leaks to third parties.

✓Strict-Transport-SecurityPresent

max-age=16070400; includeSubDomains

Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.

✓X-Content-Type-OptionsPresent

nosniff

Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.

✗X-Frame-OptionsMissing

Prevents the page from being embedded in iframes, protecting against clickjacking attacks.

How to add it:

nginx
add_header X-Frame-Options "DENY" always;
apache
Header always set X-Frame-Options "DENY"
cloudflare
Rules > Transform Rules > HTTP Response Header Modification > Set X-Frame-Options to "DENY"
✓X-XSS-ProtectionPresent

0

Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.

2 recommended security headers are missing on amservmotors.lv.

Beyond headers: infrastructure exposure

via OSN, our sister project

Security headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.

See what the internet sees about amservmotors.lvWeak headers often come with other exposure — check the full picture.

amservmotors.lv

3 scans since 7/17/2025

A

Latest: 80/100

Total Scans

3

Latest Score

80/100

First Scan

7/17/2025

Last Scan

7/17/2025

Score Trend

Security score progression over 2 scans

Scan History

DateScoreCSPHeadersIssuesAction
Jul 17, 2025
A (80)
No
4/60View →
Jul 17, 2025
A (80)
No
4/60View →

Show off your security grade

Embed this badge on your site or README. It updates automatically after each scan and links back to this report.

HeaderTest security grade: A (80/100) for amservmotors.lv
HTML
<a href="https://headertest.com/results/amservmotors.lv" title="Security headers grade for amservmotors.lv — HeaderTest">
  <img src="https://headertest.com/api/badge/amservmotors.lv" alt="HeaderTest security grade: A (80/100) for amservmotors.lv" />
</a>
Markdown
[![HeaderTest security grade: A (80/100) for amservmotors.lv](https://headertest.com/api/badge/amservmotors.lv)](https://headertest.com/results/amservmotors.lv)