cvbankas.lt
Grade F · 0/100 · 4/7 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
Security
0 / 100Critical security vulnerabilities — CSP provides minimal protection.
Compliance
0 / 100Non-compliant — CSP implementation is incomplete or report-only.
Best Practices
0 / 100Best practices largely absent — review CSP configuration.
CSP Analysis
This site does not set a Content-Security-Policy HTTP header. Without CSP, browsers allow all inline scripts, eval(), and resources from any origin, leaving the site vulnerable to Cross-Site Scripting (XSS) attacks.
Security Headers
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
How to add it:
add_header Cross-Origin-Opener-Policy "same-origin" always;Header always set Cross-Origin-Opener-Policy "same-origin"Rules > Transform Rules > HTTP Response Header Modification > Set Cross-Origin-Opener-Policy to "same-origin"Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
How to add it:
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"Rules > Transform Rules > HTTP Response Header Modification > Set Permissions-Policy valueno-referrer-when-downgrade
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
max-age=31536000; includeSubDomains
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
sameorigin
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
2 recommended security headers are missing on cvbankas.lt.
Issues Found
- •No Content Security Policy (CSP) header detected - site is vulnerable to XSS attackscritical
- •Without CSP, browsers allow all inline scripts, eval(), and resources from any origincritical
- •Missing security header: Cross-Origin-Opener-Policymedium
- •Missing security header: X-XSS-Protectionmedium
- •Missing security header: Permissions-Policymedium
Recommendations
- →Implement a Content Security Policy header to protect against XSS and data injection attacks
- →Start with a report-only policy (Content-Security-Policy-Report-Only) to identify required resources before enforcing
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
cvbankas.lt
3 scans since 7/15/2025
Latest: 0/100
Total Scans
3
Latest Score
0/100
First Scan
7/15/2025
Last Scan
7/8/2026
Security
0 / 100Critical security vulnerabilities — CSP provides minimal protection.
Compliance
0 / 100Non-compliant — CSP implementation is incomplete or report-only.
Best Practices
0 / 100Best practices largely absent — review CSP configuration.
Score Trend
Security score progression over 2 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/cvbankas.lt" title="Security headers grade for cvbankas.lt — HeaderTest">
<img src="https://headertest.com/api/badge/cvbankas.lt" alt="HeaderTest security grade: F (0/100) for cvbankas.lt" />
</a>[](https://headertest.com/results/cvbankas.lt)