insite.hr
Grade A+ · 100/100 · 6/7 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
Security
100 / 100Excellent security posture with strong CSP protections in place.
Compliance
87 / 100Mostly compliant but some directives or headers are missing.
Best Practices
47 / 100Few best practices adopted — significant room for improvement.
CSP Analysis
default-src 'self' ; script-src 'self' 'nonce-/HNyILtJxT4AG7tMtPBrrg==' 'strict-dynamic' https://cdn-cookieyes.com https://*.google-analytics.com https://*.googletagmanager.com https://snap.licdn.com ; style-src 'self' 'unsafe-hashes' 'sha256-uzDDk89laNK28n/mIYBVc9mXa9sg5ZfO/2tGfHfGtn8=' 'sha256-qye64+4AXZikGcnqmqFCOx55Lk4fa9HnkxNWNmKTB5M=' 'sha256-rrgg/HEKNbUhxr1kdjLTrHDAPVFQnRzQSxs/0xY0OrI=' 'sha256-K/uXRJLAU4TQZKQpUrkndJhdgEwkOWlArIgJbwM/tqE=' 'sha256-goU7+khjVhwA/4QfpE8BPblMcreeLRIlDVSkt6cd+mk=' 'sha256-AVTMPWKpc76zgNDd5aJeueuYlRjXEnhlc0yzr3rOrtA=' 'sha256-XvHO25pLu9BbvoPy2cVt3ssF5VYvCC2Hbr43cJ4bGro=' 'sha256-eg3Amn5WciAJjNLgkdTH67VG5XxFuBjUtFRs0WhO3rs=' 'sha256-qmH2R8RQecav7rfNisfgh9t/26LsGt6+nX6f56kSDVU=' 'sha256-HP16i0ARHAuKgo817AJXOqioTdsWnRo2V9XTWrt8QHo=' 'sha256-zC13V9VNhK/W88newL4h8SRAZHcvW7S2aUuArDnuPX8=' 'sha256-E/fw9POsVhiBgAXzyAort7xp+Zsis2nakMyCgmdMkhw=' 'sha256-+Da7S45X0Gwgp4aWoBQ21znUz2mLy/DauJvgfujZtj8=' 'sha256-SZ07T6Fd6CABoN1lL+VdOgvCyBYX2t0hLUk6kWfhtmw=' 'sha256-a0t91NkqcUI4fx/HaySE2mWiIwSoBi4E9G2Bdn/JuXI=' 'sha256-biLFinpqYMtWHmXfkA1BPeCY0/fNt46SAZ+BBk5YUog=' 'sha256-5qMZ3spQ8kQPuOwHc6By0bD1+arec8zDYViat0jB2FY=' 'sha256-Y6sHZaiwdMfqGmJ2eYK/j4IgW5HVELhdiu6AAY6X2Jo=' 'sha256-Y6sHZaiwdMfqGmJ2eYK/j4IgW5HVELhdiu6AAY6X2Jo=' 'sha256-1ZHOxacqW20jGbWtfy1R05mVC/ES8aA6VLuyObzMt+k=' 'sha256-B+o7OQj+htwIY0nDCeSh0GDnTLN1K1/e8XG2w3AhkPs=' 'sha256-8WXYwTF/M8ojyjlTdAmnCB8ETqu2c4I095JGWnNbEq4=' 'sha256-8WXYwTF/M8ojyjlTdAmnCB8ETqu2c4I095JGWnNbEq4=' 'sha256-X1tN7BpjjC/IgT5Wpon6lUaqR+rATCeXJjp5ldATaNo=' 'sha256-zTHeI5Pln9GHDhP+bLUEJURF/yHKpyURvh2MaMkhDFY=' 'sha256-r8f0k/E5UGsgLzj6aKcUe897GrbrFguaMNgD7lcw8wQ=' 'sha256-+YWRMZ88jMyO7jVlBA52tZADiPobPIUA8LAWee68Fvs=' 'sha256-V6sXYErsyFibwEnV/Y4+e77nAB0qt/IhD+gC7APMahg=' 'sha256-Yw0iM6xAr93lfK5wTLhtIr8VHRrUk7rhBNAAgE6kC4o=' 'sha256-ZnJA7jIoBdSXUBKuGPsJdpT3PWUNJbT8lY3QR8/UFbs=' 'sha256-TX+/0+DadHQ2oi/ytUsA16izf+LXLB4RxF5e15zPNy4=' 'sha256-wTpSASU5A+/ioeCyuAMmWjKbBkrSqtebPvUTeJr8+RA=' 'sha256-t7jLkzFendOF5KSBGg9b0+Fzb4/8pVmQoL2NvKUu5hQ=' 'sha256-t7jLkzFendOF5KSBGg9b0+Fzb4/8pVmQoL2NvKUu5hQ=' ; font-src 'self' data:; img-src 'self' data: https:; connect-src 'self' https://cdn-cookieyes.com https://log.cookieyes.com https://px.ads.linkedin.com https://*.google-analytics.com https://*.googletagmanager.com https://www.google.com ; frame-src https://maps.google.com https://www.google.com ;base-uri 'self' ;
Directive Analysis
Missing Directives
Strict-Dynamic Analysis
Security Headers
same-origin
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
camera=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
strict-origin-when-cross-origin
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
max-age=31536000; includeSubDomains
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
SAMEORIGIN
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
Issues Found
- •CRITICAL: 'https:' in img-src allows scripts from ANY HTTPS domaincritical
- •Duplicate value 'sha256-8WXYwTF/M8ojyjlTdAmnCB8ETqu2c4I095JGWnNbEq4=' in style-src directiveinfo
- •Duplicate value 'sha256-Y6sHZaiwdMfqGmJ2eYK/j4IgW5HVELhdiu6AAY6X2Jo=' in style-src directiveinfo
- •Duplicate value 'sha256-t7jLkzFendOF5KSBGg9b0+Fzb4/8pVmQoL2NvKUu5hQ=' in style-src directiveinfo
- •Info: 'data:' URI in font-srcinfo
- •Info: 'data:' URI in img-srcinfo
- •Missing HIGH directive frame-ancestors (Framing control - prevents clickjacking)high
- •Missing HIGH directive object-src (Plugin control - should be 'none')high
- •Missing MEDIUM directive form-action (Form submission control - prevents form hijacking)medium
- •Whitelist entries ["https://cdn-cookieyes.com", "https://*.google-analytics.com", "https://*.googletagmanager.com"]... are ignored when strict-dynamic is present (CSP3 behavior)medium
Recommendations
- →Add form-action directive with appropriate restrictions
- →Add frame-ancestors directive with appropriate restrictions
- →Add object-src directive with appropriate restrictions
- →Consider implementing a stricter Content Security Policy
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
insite.hr
26 scans since 6/7/2026
Latest: 100/100
Total Scans
26
Latest Score
100/100
First Scan
6/7/2026
Last Scan
9/18/2026
Security
100 / 100Excellent security posture with strong CSP protections in place.
Compliance
87 / 100Mostly compliant but some directives or headers are missing.
Best Practices
47 / 100Few best practices adopted — significant room for improvement.
Score Trend
Security score progression over 26 scans
Scan History
| Date | Score | CSP | Headers | Issues | Action |
|---|---|---|---|---|---|
| Sep 18, 2026 | A+ (100) | Yes | 6/7 | 10 | View → |
| Sep 18, 2026 | A+ (100) | Yes | 6/7 | 10 | View → |
| Sep 18, 2026 | F (0) | No | 6/7 | 3 | View → |
| Sep 18, 2026 | F (0) | No | 6/7 | 3 | View → |
| Sep 18, 2026 | F (0) | No | 6/7 | 3 | View → |
| Sep 17, 2026 | A+ (90) | Yes | 6/7 | 9 | View → |
| Jun 19, 2026 | A+ (100) | Yes | 6/7 | 7 | View → |
| Jun 9, 2026 | A+ (100) | Yes | 6/7 | 8 | View → |
| Jun 8, 2026 | A+ (100) | Yes | 6/7 | 8 | View → |
| Jun 8, 2026 | A+ (100) | Yes | 6/7 | 8 | View → |
| Jun 8, 2026 | A+ (100) | Yes | 6/7 | 8 | View → |
| Jun 8, 2026 | A+ (100) | Yes | 6/7 | 8 | View → |
| Jun 8, 2026 | A+ (94) | Yes | 6/7 | 9 | View → |
| Jun 8, 2026 | A+ (94) | Yes | 6/7 | 9 | View → |
| Jun 7, 2026 | F (27) | Yes | 6/7 | 22 | View → |
| Jun 7, 2026 | A+ (98) | Yes | 6/7 | 6 | View → |
| Jun 7, 2026 | A+ (98) | Yes | 6/7 | 6 | View → |
| Jun 7, 2026 | A+ (96) | Yes | 6/7 | 7 | View → |
| Jun 7, 2026 | A+ (100) | Yes | 6/7 | 6 | View → |
| Jun 7, 2026 | A (81) | Yes | 6/7 | 9 | View → |
| Jun 7, 2026 | F (0) | No | 0/7 | 9 | View → |
| Jun 7, 2026 | A (81) | Yes | 6/7 | 9 | View → |
| Jun 7, 2026 | B (71) | Yes | 5/7 | 10 | View → |
| Jun 7, 2026 | D (56) | Yes | 5/7 | 11 | View → |
| Jun 7, 2026 | F (0) | No | 0/7 | 9 | View → |
| Jun 7, 2026 | F (0) | No | 5/7 | 4 | View → |
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/insite.hr" title="Security headers grade for insite.hr — HeaderTest">
<img src="https://headertest.com/api/badge/insite.hr" alt="HeaderTest security grade: A+ (100/100) for insite.hr" />
</a>[](https://headertest.com/results/insite.hr)