eneba.lt
Grade F · 14/100 · 2/7 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
Security
14 / 100Critical security vulnerabilities — CSP provides minimal protection.
Compliance
36 / 100Major compliance issues — missing critical directives and headers.
Best Practices
7 / 100Best practices largely absent — review CSP configuration.
CSP Analysis
report-uri https://sentry.eneba.com/api/6/security/?sentry_key=102de17feb49405fadcbb032c33331d1&sentry_release=20260708-123827; report-to csp-endpoint; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://metrics.nsureapi.com https://nsure.eneba.com https://device.maxmind.com https://fpnpmcdn.net https://connect.facebook.net https://*.clarity.ms https://eneba.atlassian.net https://static.eneba.games https://assets.eneba.games https://challenges.cloudflare.com https://mx.eneba.com https://widget.trustpilot.com https://apps.rokt.com https://js.braintreegateway.com https://assets.braintreegateway.com https://www.paypalobjects.com https://www.paypal.com https://c.paypal.com https://*.cardinalcommerce.com https://*.js.stripe.com https://js.stripe.com https://checkoutshopper-live-us.adyen.com https://checkoutshopper-live.adyen.com https://cdn.safecharge.com https://pay.google.com https://static.dlocal.com https://ebanx-js.ebanx.com https://beacon.riskified.com https://i.k-analytix.com https://checkout-web-components.checkout.com https://applepay.cdn-apple.com https://js.tazapay.com https://service.tazapay.com https://newsletter.ene.ba https://an.gr-wcon.com https://us-an.gr-cdn.com https://ga2.getresponse.com https://m.gr-cdn-e.eu https://*.forter.com https://d1qmrxg9gbf226.cloudfront.net https://d229oaghhl3bjt.cloudfront.net https://d1141abz4ln14s.cloudfront.net https://d1w9sasay4s756.cloudfront.net https://d3bejklh892qn.cloudfront.net https://d2nww8zpyj5pk0.cloudfront.net https://d2w2nqfk3z9hdt.cloudfront.net https://d27623md02evp.cloudfront.net https://*.signifyd.com https://h64.online-metrix.net;
Directive Analysis
Missing Directives
Security Headers
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
How to add it:
add_header Cross-Origin-Opener-Policy "same-origin" always;Header always set Cross-Origin-Opener-Policy "same-origin"Rules > Transform Rules > HTTP Response Header Modification > Set Cross-Origin-Opener-Policy to "same-origin"Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
How to add it:
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"Rules > Transform Rules > HTTP Response Header Modification > Set Permissions-Policy valuestrict-origin-when-cross-origin
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
How to add it:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"SSL/TLS > Edge Certificates > Enable HSTS (toggle on, set max-age to 12 months, enable includeSubDomains)Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
How to add it:
add_header X-Content-Type-Options "nosniff" always;Header always set X-Content-Type-Options "nosniff"Rules > Transform Rules > Managed Transforms > Enable "Add X-Content-Type-Options header"SAMEORIGIN
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
4 recommended security headers are missing on eneba.lt.
Issues Found
- •Deprecated: 'report-uri' is deprecated in CSP Level 3. Use 'report-to' directive instead.info
- •Missing CRITICAL directive default-src (Base fallback directive)critical
- •Missing HIGH directive base-uri (Base URI control - prevents base tag injection)high
- •Missing HIGH directive frame-ancestors (Framing control - prevents clickjacking)high
- •Missing HIGH directive object-src (Plugin control - should be 'none')high
- •Missing MEDIUM directive connect-src (API/XHR control - prevents data exfiltration)medium
- •Missing MEDIUM directive font-src (Font source control)medium
- •Missing MEDIUM directive form-action (Form submission control - prevents form hijacking)medium
- •Missing MEDIUM directive img-src (Image source control)medium
- •Missing MEDIUM directive style-src (Stylesheet source control)medium
- •Missing security header: Cross-Origin-Opener-Policymedium
- •Missing security header: Permissions-Policymedium
- •Missing security header: Strict-Transport-Securitymedium
- •Missing security header: X-Content-Type-Optionsmedium
- •No nonces or hashes used for script-srcmedium
- •Unsafe eval() execution allowed in script-srchigh
- •Unsafe inline execution allowed in script-srchigh
Recommendations
- →Add base-uri directive with appropriate restrictions
- →Add connect-src directive with appropriate restrictions
- →Add default-src directive with appropriate restrictions
- →Add font-src directive with appropriate restrictions
- →Add form-action directive with appropriate restrictions
- →Add frame-ancestors directive with appropriate restrictions
- →Add img-src directive with appropriate restrictions
- →Add object-src directive with appropriate restrictions
- →Add style-src directive with appropriate restrictions
- →Consider implementing a stricter Content Security Policy
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
eneba.lt
4 scans since 7/15/2025
Latest: 14/100
Total Scans
4
Latest Score
14/100
First Scan
7/15/2025
Last Scan
7/8/2026
Security
14 / 100Critical security vulnerabilities — CSP provides minimal protection.
Compliance
36 / 100Major compliance issues — missing critical directives and headers.
Best Practices
7 / 100Best practices largely absent — review CSP configuration.
Score Trend
Security score progression over 3 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/eneba.lt" title="Security headers grade for eneba.lt — HeaderTest">
<img src="https://headertest.com/api/badge/eneba.lt" alt="HeaderTest security grade: F (14/100) for eneba.lt" />
</a>[](https://headertest.com/results/eneba.lt)