sotsiaalministeerium.ee
Grade A · 80/100 · 4/6 security headers present
Security Score
Security Headers
CSP Violations
Issues Found
Recommendations
CSP Analysis
default-src 'self'; connect-src 'self' *.siteimprove.com https://www.google-analytics.com https://www.googletagmanager.com https://search.service.vportal.ee/v1/search/sm https://search.service.vportal.ee/v1/globalsearch/total https://form.service.vportal.ee/v1/ https://search.service.vportal.ee/v1/events/sm https://inaadress.maaamet.ee; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://*.rocket.chat https://www.google.com https://www.youtube.com https://*.vimeo.com https://*.siteimprove.com https://tableauapp.tehik.ee https://e.infogram.com/ https://rtk.ee/ https://sm.ee/show_node_paragraph/2434/82ba387c-3181-488a-b2f7-180f9633e6b2 https://sm.ee/show_node_paragraph/221/31c7085f-c6b8-465f-949f-dd1379a40dfe https://kriis.prelive.vportal.ee/show_node_paragraph/879/9805f208-da39-4328-8f31-1bdc1fea7eaa https://kriis.ee/show_node_paragraph/879/9805f208-da39-4328-8f31-1bdc1fea7eaa https://sm.web.tehik.ee/show_node_paragraph/2618/9a314991-ebe6-4e3a-ad66-290aa1b2bee2 https://tableauapp.test.tehik.ee/t/SOM/views/Indikaatoridkoos/Indikaatorid_koos https://tableauapp.tehik.ee/t/SOM/views/SHindikaatorid/Indikaatorid_koos https://tableauapp.tehik.ee/t/SOM/views/Indikaatoridkoos/Indikaatorid_koos https://https//public.tableau.com/app/profile/som.anso/viz/SH_indikaatorid_public/Indikaatorid_koos https://rtk.ee/show_node_paragraph/6154/7311560b-07b6-4a08-afb1-790299d62c8c https://www.youtube.com/live/qAF7uRs_vHA https://xgis.maaamet.ee; img-src 'self' data: https://www.google-analytics.com *.openstreetmap.org https://i.ytimg.com https://pbs.twimg.com 6168367.global.siteimproveanalytics.io https://www.googletagmanager.com *.fbcdn.net *.cdninstagram.com https://inaadress.maaamet.ee https://unpkg.com *.maaamet.ee *.cloudflare.com; script-src 'self' 'unsafe-inline' https://*.rocket.chat https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.siteimprove.net/cms/overlay.js blob: https://browser-update.org static.cloudflareinsights.com ajax.cloudflare.com https://ajax.cloudflare.com https://static.cloudflareinsights.com https://siteimproveanalytics.com cdn.jsdelivr.net cdnjs.cloudflare.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://inaadress.maaamet.ee https://unpkg.com unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://*.rocket.chat https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.siteimprove.net/cms/overlay.js https://browser-update.org https://talendipank.ee static.cloudflareinsights.com ajax.cloudflare.com https://siteimproveanalytics.com https://tableauapp.tehik.ee https://e.infogram.com/ cdn.jsdelivr.net cdnjs.cloudflare.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://inaadress.maaamet.ee https://unpkg.com unpkg.com; style-src 'self' 'unsafe-inline' https://www.gstatic.com cdnjs.cloudflare.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://www.gstatic.com cdnjs.cloudflare.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com https://inaadress.maaamet.ee; frame-ancestors 'self' https://rtk.ee/; upgrade-insecure-requests
Directive Analysis
Security Headers
Restricts which browser features (camera, microphone, geolocation) the page can use, limiting attack surface.
How to add it:
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"Rules > Transform Rules > HTTP Response Header Modification > Set Permissions-Policy valueno-referrer-when-downgrade
Controls how much referrer information is sent with requests, preventing data leaks to third parties.
max-age=31536000
Forces browsers to use HTTPS for all future requests, preventing man-in-the-middle attacks and SSL stripping.
nosniff
Prevents browsers from MIME-sniffing responses away from the declared Content-Type, blocking drive-by downloads.
DENY
Prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
How to add it:
add_header X-XSS-Protection "0" always;Header always set X-XSS-Protection "0"Rules > Transform Rules > HTTP Response Header Modification > Set X-XSS-Protection to "0"2 recommended security headers are missing on sotsiaalministeerium.ee.
Beyond headers: infrastructure exposure
via OSN, our sister projectSecurity headers protect the browser. OSN maps what's exposed underneath — servers, open ports, known CVEs, DNS and WHOIS.
sotsiaalministeerium.ee
3 scans since 7/19/2025
Latest: 80/100
Total Scans
3
Latest Score
80/100
First Scan
7/19/2025
Last Scan
7/19/2025
Score Trend
Security score progression over 2 scans
Show off your security grade
Embed this badge on your site or README. It updates automatically after each scan and links back to this report.
<a href="https://headertest.com/results/sotsiaalministeerium.ee" title="Security headers grade for sotsiaalministeerium.ee — HeaderTest">
<img src="https://headertest.com/api/badge/sotsiaalministeerium.ee" alt="HeaderTest security grade: A (80/100) for sotsiaalministeerium.ee" />
</a>[](https://headertest.com/results/sotsiaalministeerium.ee)