This scan was made by Website Security Scanner at webscanner.unofix.no

73/100
Can be improved

Scanned URL: tormentacgi.com

2026-01-04 22:35:19
πŸ›‘οΈ
Security Headers
0
πŸ”’
SSL / HTTPS
100
πŸͺ
Cookies
100
πŸ“‚
Exposed Files
90
πŸ–₯️
Server Info
100
❌ Security Headers 0%

Security headers are HTTP response headers that tell the browser how to handle a website’s content in a secure way.

0 of 8 recommended security headers found (0% score)

Header Status Value Description
X-Frame-Options ❌ Not set Protects against clickjacking attacks. Hackers can load your page in an invisible iframe and trick users into clicking buttons they cannot see (e.g. "Transfer money"). Status: Not set.
X-Content-Type-Options ❌ Not set Prevents MIME-sniffing. A malicious file pretending to be an image can be executed as JavaScript and steal user data. Status: Not set.
Strict-Transport-Security ❌ Not set Enforces HTTPS usage (HSTS). Without HTTPS, attackers on the same WiFi network can intercept all communication and steal passwords in plain text. Status: Not set.
Content-Security-Policy ❌ Not set Controls which resources can be loaded. Malicious scripts from third parties can run on your page and steal user data or spread malware. Status: Not set.
Referrer-Policy ❌ Not set Controls what referrer information is sent. Sensitive URLs (e.g. /reset-password?token=abc123) can leak to third parties via analytics or ads. Status: Not set.
Permissions-Policy ❌ Not set Controls access to browser features (camera, microphone, GPS). Malicious code or third-party scripts can secretly activate camera/microphone and spy on the user. Status: Not set.
Cross-Origin-Opener-Policy ❌ Not set Isolates your window from cross-origin windows. A malicious popup window can read data from your page via window.opener and steal sensitive information. Status: Not set.
Cross-Origin-Resource-Policy ❌ Not set Controls who can load your resources. Other websites can steal bandwidth by hotlinking to your images, or read pixel data from cross-origin images. Status: Not set.
⚠️ Exposed Files & Information Disclosure 90%

2 sensitive file(s) found publicly accessible. Immediate action required.

Item Information
πŸ” Detected Technology WordPress
/readme.html
πŸ”΅ LOW
Version information is exposed
May reveal WordPress version number
/license.txt
πŸ”΅ LOW
Version information is exposed
May reveal WordPress version number
βœ… SSL/TLS Security 100%

Valid SSL certificate from trusted Certificate Authority. Certificate expires in 329 days.

πŸ“œ SSL Certificate Information
Status βœ… Valid
Issued To tormentacgi.com
Issued By Sectigo Public Server Authentication CA DV R36
Valid Until 2026-11-30 00:59:59
Days Until Expiry 329 days
βœ… Cookie Security 100%

No Set-Cookie headers found in the initial response. Note: cookies may still be set client-side (JavaScript) after page load.

Cookie Name Security Flags Score Risk Issues