locator.popular.com
Grade C · 65/100 · 6/7 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
Security
65 / 100Moderate security gaps found — unsafe directives or weak source restrictions.
Compliance
100 / 100CSP implementation follows recommended standards and specifications.
Best Practices
75 / 100Good practices in place but missing some important optimizations.
CSP Analysis
upgrade-insecure-requests; base-uri 'self'; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://scripts.clarity.ms https://www.clarity.ms https://bancopopular.my.site.com https://c.la4-c4-ph2.salesforceliveagent.com https://cdn.datatables.net https://cdn.evgnet.com/beacon/bancopopular/production/scripts/evergage.min.js https://connect.facebook.net https://form.popular.com https://maps.googleapis.com https://service.force.com/embeddedservice/5.0/esw.min.js https://siteintercept.qualtrics.com https://t.popular.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://zncnofyf5s9uktcec-popular.siteintercept.qualtrics.com/SIE/ https://api.swiftype.com https://capi-automation.s3.us-east-2.amazonaws.com; style-src 'self' 'unsafe-inline' https://bancopopular.us-4.evergage.com https://bancopopular.my.site.com https://fonts.googleapis.com https://form.popular.com https://popular.tfaforms.net https://stackpath.bootstrapcdn.com https://www.gstatic.com; object-src 'none'; connect-src 'self' data: https://report.clarity.ms https://a.clarity.ms https://b.clarity.ms https://c.clarity.ms https://d.clarity.ms https://e.clarity.ms https://f.clarity.ms https://g.clarity.ms https://h.clarity.ms https://i.clarity.ms https://j.clarity.ms https://k.clarity.ms https://l.clarity.ms https://m.clarity.ms https://n.clarity.ms https://o.clarity.ms https://p.clarity.ms https://q.clarity.ms https://r.clarity.ms https://s.clarity.ms https://t.clarity.ms https://u.clarity.ms https://v.clarity.ms https://w.clarity.ms https://x.clarity.ms https://y.clarity.ms https://z.clarity.ms https://www.clarity.ms https://popular.tfaforms.net https://app-ccm-telebanco.azurewebsites.net https://tools.popularweb.com https://tools.popular.com https://apps.popular.com https://forms.popular.com https://region1.analytics.google.com https://analytics.google.com https://app-jwtvalidator-prod-001.azurewebsites.net https://app-locator-prod-cl.azurewebsites.net https://bancopopular.my.salesforce-scrt.com https://bancopopular.us-4.evergage.com https://blog.popular.com https://maps.googleapis.com https://mpc2-prod-24-is5qnl632q-uw.a.run.app https://siteintercept.qualtrics.com https://stats.g.doubleclick.net https://ad.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.google.com.pr https://www.googletagmanager.com https://form.popular.com https://places.googleapis.com https://bancopopular.my.site.com; font-src 'self' data: https://bancopopular.us-4.evergage.com https://fonts.gstatic.com https://stackpath.bootstrapcdn.com; form-action 'self' https://form.popular.com https://popular.iad1.qualtrics.com; frame-src 'self' https://www.popular.com https://www.googletagmanager.com https://bancopopular.my.site.com https://popular.iad1.qualtrics.com https://www.google.com https://www.youtube-nocookie.com https://www.youtube.com; frame-ancestors 'self' https://mibanco.popular.com https://mobile-mibanco.popular.com; img-src 'self' data: https://media.popular.com https://connect.facebook.net https://report.clarity.ms https://a.clarity.ms https://b.clarity.ms https://c.clarity.ms https://d.clarity.ms https://e.clarity.ms https://f.clarity.ms https://g.clarity.ms https://h.clarity.ms https://i.clarity.ms https://j.clarity.ms https://k.clarity.ms https://l.clarity.ms https://m.clarity.ms https://n.clarity.ms https://o.clarity.ms https://p.clarity.ms https://q.clarity.ms https://r.clarity.ms https://s.clarity.ms https://t.clarity.ms https://u.clarity.ms https://v.clarity.ms https://w.clarity.ms https://x.clarity.ms https://y.clarity.ms https://z.clarity.ms https://www.clarity.ms https://c.bing.ms https://c.bing.com https://fonts.gstatic.com https://assets.dealerappcenter.com https://i.ytimg.com https://img.youtube.com https://maps.gstatic.com https://maps.googleapis.com https://siteintercept.qualtrics.com https://www.facebook.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://beacon.krxd.net; manifest-src 'self'; media-src 'self'; worker-src 'none'; script-src-elem 'self' 'unsafe-inline' https://bancopopular.us-4.evergage.com https://scripts.clarity.ms https://www.clarity.ms https://popular.tfaforms.net https://api.swiftype.com https://ajax.googleapis.com https://www.google.com https://www.gstatic.com https://form.popular.com https://maps.googleapis.com https://maps.gstatic.com https://t.popular.com https://googleads.g.doubleclick.net https://capi-automation.s3.us-east-2.amazonaws.com https://www.google-analytics.com https://cdn.evgnet.com https://connect.facebook.com https://connect.facebook.net https://bancopopular.my.site.com https://siteintercept.qualtrics.com https://zncnofyf5s9uktcec-popular.siteintercept.qualtrics.com https://service.force.com https://cdn.datatables.net https://c.la4-c4-ph2.salesforceliveagent.com https://www.googletagmanager.com https://www.youtube.com https://static.hotjar.com/c/hotjar-1358674.js; report-uri https://o4509809260036096.ingest.us.sentry.io/api/4509827512336384/security/?sentry_key=7d137c543ed7e08e82c7942c93fb4f3b; report-to sentry;
Directive Analysis
Security Headers
same-origin-allow-popups
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
geolocation=(self), microphone=()
Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
strict-origin-when-cross-origin
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
max-age=31536000; includeSubdomains
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
SAMEORIGIN
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
Issues Found
- •CDN RISK: 'ajax.googleapis.com' in script-src-elem - Hosts Angular libraries that can bypass CSP with strict-dynamicmedium
- •Deprecated: 'report-uri' is deprecated in CSP Level 3. Use 'report-to' directive instead.info
- •Info: 'data:' URI in connect-srcinfo
- •Info: 'data:' URI in font-srcinfo
- •Info: 'data:' URI in img-srcinfo
- •No nonces or hashes used for script-srcmedium
- •Unsafe eval() execution allowed in script-srchigh
- •Unsafe inline execution allowed in script-srchigh
- •Unsafe inline execution allowed in script-src-elemhigh
- •Unsafe inline execution allowed in style-srchigh
Recommendations
- →Consider implementing a stricter Content Security Policy
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
locator.popular.com
5 scans since 7/31/2026
Latest: 65/100
Total Scans
5
Latest Score
65/100
First Scan
7/31/2026
Last Scan
9/3/2026
Security
65 / 100Moderate security gaps found — unsafe directives or weak source restrictions.
Compliance
100 / 100CSP implementation follows recommended standards and specifications.
Best Practices
75 / 100Good practices in place but missing some important optimizations.
Score Trend
Security score progression over 5 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/locator.popular.com" title="Security headers grade for locator.popular.com — HeaderTest">
<img src="https://headertest.com/api/badge/locator.popular.com" alt="HeaderTest security grade: C (65/100) for locator.popular.com" />
</a>[](https://headertest.com/results/locator.popular.com)