{ "scan": { "algorithmVersion": 4, "grade": "C", "error": null, "score": 55, "statusCode": 200, "testsFailed": 3, "testsPassed": 7, "testsQuantity": 10, "responseHeaders": { "server": "nginx", "date": "Sun, 24 May 2026 05:37:39 GMT", "content-type": "text/html;charset=ISO-8859-1", "content-length": "126", "connection": "close", "cache-control": "private", "set-cookie": [ "JSESSIONID=313F34531C60840C76BA85B18B2EBA8F; Path=/; Secure; HttpOnly" ], "strict-transport-security": "max-age=15780000; includeSubDomains", "content-security-policy": "default-src *; script-src 'self'; script-src-elem 'self' 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:" } }, "tests": { "content-security-policy": { "expectation": "csp-implemented-with-no-unsafe", "pass": false, "result": "csp-implemented-with-unsafe-inline", "scoreModifier": -20, "data": { "default-src": [ "*" ], "script-src": [ "'self'" ], "script-src-elem": [ "'self'", "'unsafe-inline'" ], "script-src-attr": [ "'self'", "'unsafe-inline'" ], "style-src": [ "'self'", "'unsafe-inline'" ], "img-src": [ "'self'", "data:" ] }, "http": true, "meta": false, "policy": { "antiClickjacking": false, "defaultNone": false, "insecureBaseUri": true, "insecureFormAction": true, "insecureSchemeActive": false, "insecureSchemePassive": false, "strictDynamic": false, "unsafeEval": false, "unsafeInline": true, "unsafeInlineStyle": true, "unsafeObjects": true }, "numPolicies": 1 }, "cookies": { "expectation": "cookies-secure-with-httponly-sessions", "pass": true, "result": "cookies-secure-with-httponly-sessions", "scoreModifier": 0, "data": { "JSESSIONID": { "domain": "fme.discomap.eea.europa.eu", "httponly": true, "path": "/", "port": null, "secure": true } }, "sameSite": false }, "cross-origin-resource-sharing": { "expectation": "cross-origin-resource-sharing-not-implemented", "pass": true, "result": "cross-origin-resource-sharing-not-implemented", "scoreModifier": 0, "data": null }, "redirection": { "expectation": "redirection-to-https", "pass": true, "result": "redirection-to-https", "scoreModifier": 0, "destination": "https://fme.discomap.eea.europa.eu/", "redirects": true, "route": [ "http://fme.discomap.eea.europa.eu/", "https://fme.discomap.eea.europa.eu/" ], "statusCode": 200 }, "referrer-policy": { "expectation": "referrer-policy-private", "pass": true, "result": "referrer-policy-not-implemented", "scoreModifier": 0, "data": null, "http": false, "meta": false }, "strict-transport-security": { "expectation": "hsts-implemented-max-age-at-least-six-months", "pass": true, "result": "hsts-implemented-max-age-at-least-six-months", "scoreModifier": 0, "data": "max-age=15780000; includeSubDomains", "includeSubDomains": true, "maxAge": 15780000, "preload": false, "preloaded": false }, "subresource-integrity": { "expectation": "sri-implemented-and-external-scripts-loaded-securely", "pass": true, "result": "sri-not-implemented-but-no-scripts-loaded", "scoreModifier": 0, "data": {} }, "x-content-type-options": { "expectation": "x-content-type-options-nosniff", "pass": false, "result": "x-content-type-options-not-implemented", "scoreModifier": -5, "data": null }, "x-frame-options": { "expectation": "x-frame-options-sameorigin-or-deny", "pass": false, "result": "x-frame-options-not-implemented", "scoreModifier": -20, "data": null }, "cross-origin-resource-policy": { "expectation": "corp-implemented-with-same-site", "pass": true, "result": "corp-not-implemented", "scoreModifier": 0, "data": null, "http": false, "meta": false } } }