manodaktaras.lt
Grade B · 75/100 · 5/7 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
Security
75 / 100Good security foundation but some CSP hardening recommended.
Compliance
82 / 100Mostly compliant but some directives or headers are missing.
Best Practices
50 / 100Basic practices followed but missing important optimizations.
CSP Analysis
default-src 'none'; script-src 'nonce-KR4pHmzh9ywBNgAbwqImuK' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
Directive Analysis
Missing Directives
Security Headers
same-origin
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
same-origin
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
How to add it:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"SSL/TLS > Edge Certificates > Enable HSTS (toggle on, set max-age to 12 months, enable includeSubDomains)nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
SAMEORIGIN
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
1 recommended security header is missing on manodaktaras.lt.
Issues Found
- •CRITICAL: 'https:' in form-action allows scripts from ANY HTTPS domaincritical
- •Info: 'blob:' URI in child-srcinfo
- •Info: 'blob:' URI in frame-srcinfo
- •Info: 'blob:' URI in worker-srcinfo
- •Insecure HTTP source allowed in form-actionmedium
- •Missing HIGH directive frame-ancestors (Framing control - prevents clickjacking)high
- •Missing HIGH directive object-src (Plugin control - should be 'none')high
- •Missing MEDIUM directive font-src (Font source control)medium
- •Missing security header: Strict-Transport-Securitymedium
- •RISK: 'blob:' in worker-src allows creation of workers from dynamic blob contentmedium
- •Unsafe eval() execution allowed in script-srchigh
- •Unsafe inline execution allowed in style-srchigh
Recommendations
- →Add font-src directive with appropriate restrictions
- →Add frame-ancestors directive with appropriate restrictions
- →Add object-src directive with appropriate restrictions
- →Consider implementing a stricter Content Security Policy
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
manodaktaras.lt
3 scans since 7/16/2025
Latest: 75/100
Total Scans
3
Latest Score
75/100
First Scan
7/16/2025
Last Scan
7/8/2026
Security
75 / 100Good security foundation but some CSP hardening recommended.
Compliance
82 / 100Mostly compliant but some directives or headers are missing.
Best Practices
50 / 100Basic practices followed but missing important optimizations.
Score Trend
Security score progression over 2 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/manodaktaras.lt" title="Security headers grade for manodaktaras.lt — HeaderTest">
<img src="https://headertest.com/api/badge/manodaktaras.lt" alt="HeaderTest security grade: B (75/100) for manodaktaras.lt" />
</a>[](https://headertest.com/results/manodaktaras.lt)