Security Report Summary
R
| Redirect: | Click here to follow the redirect to https://jemputhoki.co/. | ||
|---|---|---|---|
| Site: | http://jemputhokiofficial.com/ - (Scan again over https) | ||
| IP Address: | 207.89.22.11 | ||
| Report Time: | 19 Sep 2026 23:17:30 UTC | ||
| Headers: |
|
||
| Warning: | Grade capped at A, please see warnings below. | ||
| Advanced: |
|
Missing Headers
| Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
|---|---|
| X-Content-Type-Options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
| Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
| Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Warnings
| Site is using HTTP | This site was served over HTTP and did not redirect to HTTPS. |
|---|
Raw Headers
| HTTP/1.1 | 301 Moved Permanently |
|---|---|
| Date | Sat, 19 Sep 2026 23:17:30 GMT |
| Content-Type | text/html; charset=utf-8 |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-XSS-Protection | 1; mode=block |
| Strict-Transport-Security | max-age=31536000;includeSubDomains |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| Location | https://jemputhoki.co |
| Age | 0 |
| X-Cache | MISS |
| X-Cache-Hits | 0 |
| Set-Cookie | XSRF-TOKEN=eyJpdiI6InNWWm53d09OM1FYOHBJdWdNdGUwTGc9PSIsInZhbHVlIjoiczY0RTR5S1hGQTRPeGtjS05raFRtRVRxbnQ3end6T0RheWx0Y1FtdHorbWhFR2NIUGJpMVNic09PY29acnNzNjA5bXNVNis2eVBWcmx6dWllSU5jUTU4YzhYVUVNZ2UxUURGWWhGbGNtUVR5TXFnSlJDN213d0haa1NFTm4zK0kiLCJtYWMiOiJhZjM2NjgwMDkyYmNjMjVkY2JjODAzMWRlYWY1NTc3NDg4MTdlNjBlZjY3NjY4MTVlZjY2MWRhYmMzZGFlOWM1IiwidGFnIjoiIn0%3D; expires=Sun, 20 Sep 2026 01:17:30 GMT; Max-Age=7200; path=/ |
| Set-Cookie | laravel_session=eyJpdiI6IkZvVVhIK3hHYnY0aVNpTnFtOGdqN2c9PSIsInZhbHVlIjoiZHR4b3NJWG5VbnlNWm1IUGlEYWcrZFpLS3dKVy83QmxVZ0hxUCs0em0rS2t3alBWWjFRUit2YVdGY1NxODhrUTdUUS9zeGtXRGppOXdUeU5ZeFJFQ2JqUVZmZTFOb0x5NmFlRUxJZEl3empneUlQZGUzZkFSbkhlUldBcVBuczQiLCJtYWMiOiJmYmVmMDAwZWE3NWJmZGMyZTJiYmQyMGQ3YTNkN2FmOTMyNmU3ZTA2Yzg0YjUxYTFmNTU2ZDU0NjI5NzU4ZmE0IiwidGFnIjoiIn0%3D; path=/; httponly |
| set-cookie | __cf_bm=9bnasIRmuEZsWX2QGQGVtETWCai_96DOYPXvMh3NNHk-1789859850.0132387-1.0.1.1-bGpJqjlqFRN3u5g8BG_986W0BXKIpz9TYIk2pR6AXFHbtzBba1MRZbv363hwVACOQRzRWg34Jh87oJTtMUfXCCzP5zvAGcbyfN3AeElh5G1ULTxb_fBE4CawX3zW8B41; HttpOnly; Path=/; Domain=jemputhokiofficial.com; Expires=Sat, 19 Sep 2026 23:47:30 GMT |
| set-cookie | __cflb=0H28vwrm5dNN32CyBPTJZiiJbTxGA87ghbaacuXtiWQ; HttpOnly; SameSite=Lax; Path=/; Expires=Sun, 20 Sep 2026 22:17:30 GMT |
| Server-Timing | cfCacheStatus;desc="DYNAMIC" |
| Server-Timing | cfEdge;dur=186,cfOrigin;dur=36 |
| cf-cache-status | DYNAMIC |
| Server | cloudflare |
| CF-RAY | a3dc4dde9d2286cb-DUB |
Upcoming Headers
| Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
|---|---|
| Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
| Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
| X-XSS-Protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
|---|---|
| Strict-Transport-Security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS. That said, the HSTS header must not be returned over a HTTP connection, only HTTPS. |
| Strict-Transport-Security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS. That said, the HSTS header must not be returned over a HTTP connection, only HTTPS. |
| Access-Control-Allow-Origin | This is a very lax CORS policy. Such a policy should only be used on a public CDN. |
| X-Frame-Options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
| Set-Cookie | This is not a SameSite Cookie. |
| Server | Server value has been changed. Typically you will see values like "Microsoft-IIS/8.0" or "nginx 1.7.2". |