← All Results
Domain History

bilietai.lt

Grade C · 65/100 · 6/7 security headers present

Security Score

C
65/ 100

Security Headers

6/ 7

CSP Violations

NoViolations

Issues Found

12Issues

Recommendations

1Available

Security

65 / 100

Moderate security gaps found — unsafe directives or weak source restrictions.

Compliance

100 / 100

CSP implementation follows recommended standards and specifications.

Best Practices

70 / 100

Good practices in place but missing some important optimizations.

CSP Analysis

Content Security PolicyHIGH
base-uri 'none'; font-src 'self' https: data:; form-action 'self' https: https://*.facebook.com; frame-ancestors https://store.bilietai.lt 'self'; img-src https: 'self' data: https://*.cookiebot.com https://www.googletagmanager.com; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src https://store.bilietai.lt 'self' https: 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://consent.cookiebot.com https://maps.googleapis.com https://*.instagram.com https://static.cdninstagram.com https://*.facebook.com https://*.fbcdn.net https://*.facebook.net; upgrade-insecure-requests; connect-src https://store.bilietai.lt https://www.google.lt https://www.google.ru 'self' https://pagead2.googlesyndication.com https://maps.googleapis.com https://*.tiktok.com https://*.cookiebot.com https://*.adtrafficquality.google https://www.facebook.com https://*.facebook.net https://*.google-analytics.com https://*.gstatic.com https://*.google.com https://google.com https://*.clarity.ms https://*.doubleclick.net https://*.googleadservices.com https://*.googletagmanager.com; frame-src 'self' https://www.googletagmanager.com https://consentcdn.cookiebot.com https://*.google.com https://pagead2.googlesyndication.com https://*.adtrafficquality.google https://www.youtube.com https://open.spotify.com https://*.facebook.com https://*.doubleclick.net https://*.twitch.tv https://*.soundcloud.com https://*.vimeo.com https://*.instagram.com https://*.twitter.com https://*.tiktok.com https://forms.office.com https://forms.bdev.lt https://piletilevi.visitor.videolevels.com; default-src 'self'; report-to csp-endpoint; report-uri /api/v1/csp-reports;
Directive Analysis
base-uriLOW
none
font-srcHIGH
self https: data:
•CRITICAL: 'https:' in font-src allows scripts from ANY HTTPS domain
•Info: 'data:' URI in font-src
form-actionHIGH
self https: https://*.facebook.com
•CRITICAL: 'https:' in form-action allows scripts from ANY HTTPS domain
frame-ancestorsLOW
https://store.bilietai.lt self
img-srcHIGH
https: self data: https://*.cookiebot.com https://www.googletagmanager.com
•CRITICAL: 'https:' in img-src allows scripts from ANY HTTPS domain
•Info: 'data:' URI in img-src
object-srcLOW
none
script-src-attrLOW
none
style-srcHIGH
self https: unsafe-inline
•CRITICAL: 'https:' in style-src allows scripts from ANY HTTPS domain
•Unsafe inline execution allowed in style-src
script-srcHIGH
https://store.bilietai.lt self https: unsafe-inline unsafe-eval https://www.googletagmanager.com https://consent.cookiebot.com https://maps.googleapis.com https://*.instagram.com https://static.cdninstagram.com https://*.facebook.com https://*.fbcdn.net https://*.facebook.net
•CRITICAL: 'https:' in script-src allows scripts from ANY HTTPS domain
•Unsafe inline execution allowed in script-src
•Unsafe eval() execution allowed in script-src
•No nonces or hashes used for script-src
upgrade-insecure-requestsLOW
connect-srcLOW
https://store.bilietai.lt https://www.google.lt https://www.google.ru self https://pagead2.googlesyndication.com https://maps.googleapis.com https://*.tiktok.com https://*.cookiebot.com https://*.adtrafficquality.google https://www.facebook.com https://*.facebook.net https://*.google-analytics.com https://*.gstatic.com https://*.google.com https://google.com https://*.clarity.ms https://*.doubleclick.net https://*.googleadservices.com https://*.googletagmanager.com
frame-srcLOW
self https://www.googletagmanager.com https://consentcdn.cookiebot.com https://*.google.com https://pagead2.googlesyndication.com https://*.adtrafficquality.google https://www.youtube.com https://open.spotify.com https://*.facebook.com https://*.doubleclick.net https://*.twitch.tv https://*.soundcloud.com https://*.vimeo.com https://*.instagram.com https://*.twitter.com https://*.tiktok.com https://forms.office.com https://forms.bdev.lt https://piletilevi.visitor.videolevels.com
default-srcLOW
self
report-toLOW
csp-endpoint
report-uriLOW
/api/v1/csp-reports
•Deprecated: 'report-uri' is deprecated in CSP Level 3. Use 'report-to' directive instead.

Security Headers

✓Cross-Origin-Opener-PolicyPresent

same-origin

Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.

✓Permissions-PolicyPresent

camera=(), display-capture=(), fullscreen=('self' https://www.youtube.com https://player.vimeo.com https://www.facebook.com), geolocation=(), microphone=()

Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.

✓Referrer-PolicyPresent

no-referrer

Controls how much referrer information is sent with requests, preventing data leaks to third parties.

✓Strict-Transport-SecurityPresent

max-age=15552000; includeSubDomains

Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.

✓X-Content-Type-OptionsPresent

nosniff

Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.

✓X-Frame-OptionsPresent

SAMEORIGIN

Prevents the page from being embedded in iframes, protecting against clickjacking attacks.

—X-XSS-ProtectionDeprecated

Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.

Issues Found

  • •CRITICAL: 'https:' in font-src allows scripts from ANY HTTPS domaincritical
  • •CRITICAL: 'https:' in form-action allows scripts from ANY HTTPS domaincritical
  • •CRITICAL: 'https:' in img-src allows scripts from ANY HTTPS domaincritical
  • •CRITICAL: 'https:' in script-src allows scripts from ANY HTTPS domaincritical
  • •CRITICAL: 'https:' in style-src allows scripts from ANY HTTPS domaincritical
  • •Deprecated: 'report-uri' is deprecated in CSP Level 3. Use 'report-to' directive instead.info
  • •Info: 'data:' URI in font-srcinfo
  • •Info: 'data:' URI in img-srcinfo
  • •No nonces or hashes used for script-srcmedium
  • •Unsafe eval() execution allowed in script-srchigh
  • •Unsafe inline execution allowed in script-srchigh
  • •Unsafe inline execution allowed in style-srchigh

Recommendations

  • →Consider implementing a stricter Content Security Policy

Beyond headers: infrastructure exposure

via OSN, our sister project

Security headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.

See what the internet sees about bilietai.lt

bilietai.lt

4 scans since 7/15/2025

C

Latest: 65/100

Total Scans

4

Latest Score

65/100

First Scan

7/15/2025

Last Scan

7/8/2026

Security

65 / 100

Moderate security gaps found — unsafe directives or weak source restrictions.

Compliance

100 / 100

CSP implementation follows recommended standards and specifications.

Best Practices

70 / 100

Good practices in place but missing some important optimizations.

Score Trend

Security score progression over 3 scans

Scan History

DateScoreCSPHeadersIssuesAction
Jul 8, 2026
C (65)
Yes
6/712View →
Jul 8, 2026
C (65)
Yes
6/712View →
Jul 15, 2025
F (0)
No
0/60View →

Show off your security grade

Embed this badge on your site or README. It updates automatically after each scan and links back to this report.

HeaderTest security grade: C (65/100) for bilietai.lt
HTML
<a href="https://headertest.com/results/bilietai.lt" title="Security headers grade for bilietai.lt — HeaderTest">
  <img src="https://headertest.com/api/badge/bilietai.lt" alt="HeaderTest security grade: C (65/100) for bilietai.lt" />
</a>
Markdown
[![HeaderTest security grade: C (65/100) for bilietai.lt](https://headertest.com/api/badge/bilietai.lt)](https://headertest.com/results/bilietai.lt)