This scan was made by Website Security Scanner at webscanner.unofix.no

75/100
Can be improved

Scanned URL: hu-go.hu

2026-02-08 15:48:37
πŸ›‘οΈ
Security Headers
43
πŸ”’
SSL / HTTPS
100
πŸͺ
Cookies
25
πŸ“‚
Exposed Files
100
πŸ–₯️
Server Info
100
❌ Security Headers 43%

Security headers are HTTP response headers that tell the browser how to handle a website’s content in a secure way.

4 of 8 recommended security headers found (43% score)

Header Status Value Description
X-Frame-Options βœ… SAMEORIGIN Protects against clickjacking attacks. Hackers can load your page in an invisible iframe and trick users into clicking buttons they cannot see (e.g. "Transfer money"). Value: SAMEORIGIN. Assessment: Good.
X-Content-Type-Options βœ… nosniff Prevents MIME-sniffing. A malicious file pretending to be an image can be executed as JavaScript and steal user data. Value: nosniff. Assessment: Good.
Strict-Transport-Security βœ… max-age=16070400; includeSubDomains Enforces HTTPS usage (HSTS). Without HTTPS, attackers on the same WiFi network can intercept all communication and steal passwords in plain text. Value: max-age=16070400; includeSubDomains. Assessment: Good.
Content-Security-Policy βœ… script-src 'self' 'unsafe-inline' 'unsafe-eval' www.gstatic.com www.google.com *.youtube.com maps.gstatic.com *.googleapis.com *.google-analytics.com connect.facebook.net cdnjs.cloudflare.com; frame-src 'self' www.gstatic.com www.google.com *.youtube.com *.facebook.com s-static.ak.facebook.com; object-src 'self' Controls which resources can be loaded. Malicious scripts from third parties can run on your page and steal user data or spread malware. Value: script-src 'self' 'unsafe-inline' 'unsafe-eval' www.gstatic.com www.google.com *.youtube.com maps.gstatic.com *.googleapis.com *.google-analytics.com connect.facebook.net cdnjs.cloudflare.com; frame-src 'self' www.gstatic.com www.google.com *.youtube.com *.facebook.com s-static.ak.facebook.com; object-src 'self'. Assessment: Unsafe. Notes: script-src contains unsafe-eval (high risk). script-src contains unsafe-inline (weakens XSS protection).
Referrer-Policy ❌ Not set Controls what referrer information is sent. Sensitive URLs (e.g. /reset-password?token=abc123) can leak to third parties via analytics or ads. Status: Not set.
Permissions-Policy ❌ Not set Controls access to browser features (camera, microphone, GPS). Malicious code or third-party scripts can secretly activate camera/microphone and spy on the user. Status: Not set.
Cross-Origin-Opener-Policy ❌ Not set Isolates your window from cross-origin windows. A malicious popup window can read data from your page via window.opener and steal sensitive information. Status: Not set.
Cross-Origin-Resource-Policy ❌ Not set Controls who can load your resources. Other websites can steal bandwidth by hotlinking to your images, or read pixel data from cross-origin images. Status: Not set.
βœ… Exposed Files & Information Disclosure 100%

No exposed files or directories found. Checked 49 file locations and 6 directories.

βœ… SSL/TLS Security 100%

Valid SSL certificate from trusted Certificate Authority. Certificate expires in 294 days.

πŸ“œ SSL Certificate Information
Status βœ… Valid
Issued To *.hu-go.hu
Issued By e-Szigno SSL CA 2014
Valid Until 2026-11-29 11:21:13
Days Until Expiry 294 days
❌ Cookie Security 25%

2 of 2 cookie(s) have CRITICAL security issues (25% score) - Immediate action required!

Cookie Name Security Flags Score Risk Issues
CAKEPHP
2quf...e330
❌ SecureπŸ›‘οΈ HttpOnly❌ SameSite
45% πŸ”΄ HIGH
  • Missing SameSite flag - Vulnerable to CSRF attacks
  • Missing Secure flag - Cookie can be intercepted over HTTP
  • Cookie sent to all paths (/) - Consider narrower scope if possible
CAKEPHP
osrb...so90
❌ SecureπŸ›‘οΈ HttpOnly❌ SameSite
45% πŸ”΄ HIGH
  • Missing SameSite flag - Vulnerable to CSRF attacks
  • Missing Secure flag - Cookie can be intercepted over HTTP
  • Cookie sent to all paths (/) - Consider narrower scope if possible
βœ… Server Information Disclosure 100%

1 server information header(s) disclosed. Consider hiding these to reduce attack surface.

Header Status Value Risk
Server ❌ Exposed nginx Server software disclosed (nginx) but no version number. Consider hiding this header completely.
X-Powered-By βœ… Hidden Not present Header not present (good - no information disclosure)
X-AspNet-Version βœ… Hidden Not present Header not present (good - no information disclosure)
X-AspNetMvc-Version βœ… Hidden Not present Header not present (good - no information disclosure)
X-Generator βœ… Hidden Not present Header not present (good - no information disclosure)