Skip to content
https://ok.ru

Security

· 13 checks — HTTP headers, CSP, TLS handshake, and cookie hygiene rolled into one auditable list.
SCORE
71
GRADE
C
FIX
3
REVIEW
5
PASS
5
INFO
0
Checks
13
5 PASS 5 REVIEW 3 FIX
F
Content Security Policy
Action
2 of 11 CSP checks passed
FIX
2 of 11 CSP checks passed
Info::
Raw CSP policy
Got: default-src data: 'self' 'unsafe-inline' 'unsafe-eval' ok.ru *.ok.ru odnoklassniki.ru *.odnoklassniki.ru okcdn.ru http://*.okcdn.ru https://*.okcdn.ru mycdn.me http://*.mycdn.me https://*.mycdn.me http://st-ok.cdn-vk.ru https://st-ok.cdn-vk.ru http://st-ok-pts.cdn-vk.ru https://st-ok-pts.cdn-vk.ru wss://ad.mail.ru *.mail.ru *.imgsmail.ru *.mradx.net *.serving-sys.com *.googleapis.com *.gstatic.com www.google.com https://api-maps.yandex.ru yastatic.net yandex.st *.doubleverify.com *.adsafeprotected.com https://cdn.consentmanager.net https://football.sportmail.ru *.google.ru *.google.com *.googlesyndication.com *.yandex.ru static.dzeninfra.ru connect.ok.ru https://connect.ok.ru blob:; script-src 'unsafe-inline' 'unsafe-eval' *.mail.ru https://*.mail.ru *.imgsmail.ru *.mradx.net ok.ru *.ok.ru odnoklassniki.ru *.odnoklassniki.ru okcdn.ru http://*.okcdn.ru https://*.okcdn.ru http://st-ok.cdn-vk.ru https://st-ok.cdn-vk.ru http://st-ok-pts.cdn-vk.ru https://st-ok-pts.cdn-vk.ru mycdn.me http://*.mycdn.me https://*.mycdn.me mc.yandex.ru an.yandex.ru yastatic.net yandex.st *.google-analytics.com api-maps.yandex.ru https://api-maps.yandex.ru https://clck.yandex.ru *.googleapis.com *.gstatic.com www.google.com www.youtube.com https://www.youtube.com *.ytimg.com https://*.ytimg.com *.doubleverify.com *.dvtps.com *.doubleclick.net *.googletagservices.com *.googlesyndication.com *.googleadservices.com *.goodgame.ru https://*.goodgame.ru https://*.moatads.com *.adlooxtracking.com *.adlooxtracking.ru *.adsafeprotected.com *.serving-sys.com *.serving-sys.ru *.weborama.fr *.weborama-tech.ru https://enterprise.api-maps.yandex.ru https://suggest-maps.yandex.ru https://*.hit.gemius.pl https://*.consentmanager.net https://gum.criteo.com https://football.sportmail.ru *.googletagmanager.com connect.facebook.net *.google.ru *.google.com *.googlesyndication.com yandex.ru static.dzeninfra.ru *.adtrafficquality.google; worker-src blob: 'self'; connect-src * wss: blob: data:; font-src * data: blob:; frame-src * blob: 'self'; img-src * data: blob: about:; media-src * data: blob:; object-src *; report-uri /csp/report;
Info::
default-src directive is set
Got: default-src data: 'self' 'unsafe-inline' 'unsafe-eval' ok.ru *.ok.ru odnoklassniki.ru *.odnoklassniki.ru okcdn.ru http://*.okcdn.ru https://*.okcdn.ru mycdn.me http://*.mycdn.me https://*.mycdn.me http://st-ok.cdn-vk.ru https://st-ok.cdn-vk.ru http://st-ok-pts.cdn-vk.ru https://st-ok-pts.cdn-vk.ru wss://ad.mail.ru *.mail.ru *.imgsmail.ru *.mradx.net *.serving-sys.com *.googleapis.com *.gstatic.com www.google.com https://api-maps.yandex.ru yastatic.net yandex.st *.doubleverify.com *.adsafeprotected.com https://cdn.consentmanager.net https://football.sportmail.ru *.google.ru *.google.com *.googlesyndication.com *.yandex.ru static.dzeninfra.ru connect.ok.ru https://connect.ok.ru blob:
Critical::
'unsafe-inline' found in script source
'unsafe-inline' allows inline <script> tags, defeating CSP against XSS. Remove it and use nonces or hashes instead.
Got: script-src 'unsafe-inline' 'unsafe-eval' *.mail.ru https://*.mail.ru *.imgsmail.ru *.mradx.net ok.ru *.ok.ru odnoklassniki.ru *.odnoklassniki.ru okcdn.ru http://*.okcdn.ru https://*.okcdn.ru http://st-ok.cdn-vk.ru https://st-ok.cdn-vk.ru http://st-ok-pts.cdn-vk.ru https://st-ok-pts.cdn-vk.ru mycdn.me http://*.mycdn.me https://*.mycdn.me mc.yandex.ru an.yandex.ru yastatic.net yandex.st *.google-analytics.com api-maps.yandex.ru https://api-maps.yandex.ru https://clck.yandex.ru *.googleapis.com *.gstatic.com www.google.com www.youtube.com https://www.youtube.com *.ytimg.com https://*.ytimg.com *.doubleverify.com *.dvtps.com *.doubleclick.net *.googletagservices.com *.googlesyndication.com *.googleadservices.com *.goodgame.ru https://*.goodgame.ru https://*.moatads.com *.adlooxtracking.com *.adlooxtracking.ru *.adsafeprotected.com *.serving-sys.com *.serving-sys.ru *.weborama.fr *.weborama-tech.ru https://enterprise.api-maps.yandex.ru https://suggest-maps.yandex.ru https://*.hit.gemius.pl https://*.consentmanager.net https://gum.criteo.com https://football.sportmail.ru *.googletagmanager.com connect.facebook.net *.google.ru *.google.com *.googlesyndication.com yandex.ru static.dzeninfra.ru *.adtrafficquality.google
Critical::
'unsafe-eval' found in script source
'unsafe-eval' allows eval() and similar functions, enabling code injection. Remove it.
Got: script-src 'unsafe-inline' 'unsafe-eval' *.mail.ru https://*.mail.ru *.imgsmail.ru *.mradx.net ok.ru *.ok.ru odnoklassniki.ru *.odnoklassniki.ru okcdn.ru http://*.okcdn.ru https://*.okcdn.ru http://st-ok.cdn-vk.ru https://st-ok.cdn-vk.ru http://st-ok-pts.cdn-vk.ru https://st-ok-pts.cdn-vk.ru mycdn.me http://*.mycdn.me https://*.mycdn.me mc.yandex.ru an.yandex.ru yastatic.net yandex.st *.google-analytics.com api-maps.yandex.ru https://api-maps.yandex.ru https://clck.yandex.ru *.googleapis.com *.gstatic.com www.google.com www.youtube.com https://www.youtube.com *.ytimg.com https://*.ytimg.com *.doubleverify.com *.dvtps.com *.doubleclick.net *.googletagservices.com *.googlesyndication.com *.googleadservices.com *.goodgame.ru https://*.goodgame.ru https://*.moatads.com *.adlooxtracking.com *.adlooxtracking.ru *.adsafeprotected.com *.serving-sys.com *.serving-sys.ru *.weborama.fr *.weborama-tech.ru https://enterprise.api-maps.yandex.ru https://suggest-maps.yandex.ru https://*.hit.gemius.pl https://*.consentmanager.net https://gum.criteo.com https://football.sportmail.ru *.googletagmanager.com connect.facebook.net *.google.ru *.google.com *.googlesyndication.com yandex.ru static.dzeninfra.ru *.adtrafficquality.google
Info::
No wildcard in script source
Warning::
object-src allows plugin content
Set object-src to 'none' to prevent Flash/Java plugin exploits.
Got: object-src * Expected: object-src 'none'
Warning::
base-uri directive is missing
Without base-uri, attackers can inject a <base> tag to hijack relative URLs. Set it to 'self' or 'none'.
Expected: base-uri 'self'
Warning::
frame-ancestors directive is missing
frame-ancestors controls who can embed your page, preventing clickjacking. Set it to 'self' or 'none'.
Expected: frame-ancestors 'self'
Warning::
form-action directive is missing
form-action restricts where forms can submit data, preventing form hijacking.
Expected: form-action 'self'
Info::
upgrade-insecure-requests is not set
This directive upgrades HTTP resources to HTTPS automatically, preventing mixed content.
Expected: upgrade-insecure-requests
Info::
Content-Security-Policy-Report-Only is also set
A report-only policy is active alongside the enforcing policy for monitoring.
Got: default-src data: blob: about: 'self' 'unsafe-inline' 'unsafe-eval' https: wss:; report-uri /csp/report?always;

'unsafe-inline' allows inline <script> tags, defeating CSP against XSS. Remove it and use nonces or hashes instead.

Why this matters

Unsafe value (unsafe-inline, unsafe-eval) in script-src defeats CSP's main protection — XSS injections can execute again.

Learn more

unsafe-inline allows inline <script> tags; unsafe-eval allows eval() and similar. Both are necessary for some legacy code but explicitly dangerous. Migrate to nonces (per-page random tokens) or hashes (per-script SHA-256) instead.

Source: OWASP CSP / MDN

'unsafe-eval' allows eval() and similar functions, enabling code injection. Remove it.

Why this matters

Unsafe value (unsafe-inline, unsafe-eval) in script-src defeats CSP's main protection — XSS injections can execute again.

Learn more

unsafe-inline allows inline <script> tags; unsafe-eval allows eval() and similar. Both are necessary for some legacy code but explicitly dangerous. Migrate to nonces (per-page random tokens) or hashes (per-script SHA-256) instead.

Source: OWASP CSP / MDN

Set object-src to 'none' to prevent Flash/Java plugin exploits.

Expected: object-src 'none'
Why this matters

object-src open in CSP allows Flash/PDF/plugin embedding — a now-deprecated attack vector that should be explicitly blocked.

Learn more

object-src controls <object>, <embed>, and <applet> elements. Modern sites have no need for plugins; setting `object-src 'none'` blocks an entire class of legacy XSS vectors at zero cost. If your CSP missed it, add the directive.

Source: MDN CSP

Without base-uri, attackers can inject a <base> tag to hijack relative URLs. Set it to 'self' or 'none'.

Expected: base-uri 'self'
Why this matters

Missing base-uri in CSP leaves a base-tag injection attack path open even on otherwise strict policies.

Learn more

A common omission: developers add CSP for script-src and frame-ancestors but forget base-uri. The result is a CSP that looks strict but lets an attacker rewrite every URL on the page via <base href>. Add `base-uri 'self'` to close the gap.

Source: MDN CSP

frame-ancestors controls who can embed your page, preventing clickjacking. Set it to 'self' or 'none'.

Expected: frame-ancestors 'self'
Why this matters

Security gaps expose your site and users to attacks, eroding trust.

form-action restricts where forms can submit data, preventing form hijacking.

Expected: form-action 'self'
Why this matters

Security gaps expose your site and users to attacks, eroding trust.

This directive upgrades HTTP resources to HTTPS automatically, preventing mixed content.

Expected: upgrade-insecure-requests
Why this matters

Without upgrade-insecure-requests, any HTTP subresource link survives as a mixed-content warning instead of auto-upgrading.

Learn more

Adding `upgrade-insecure-requests` to your CSP turns every http:// subresource fetch into https:// at the browser layer. One-line defense against accidental mixed content from legacy links or third-party widgets.

Source: MDN CSP

A report-only policy is active alongside the enforcing policy for monitoring.

Why this matters

Running enforcing + Report-Only in parallel lets you test stricter directives safely before promoting them.

Source: MDN CSP

Parsed Policy

default-src data:'self''unsafe-inline''unsafe-eval'ok.ru*.ok.ruodnoklassniki.ru*.odnoklassniki.ruokcdn.ruhttp://*.okcdn.ruhttps://*.okcdn.rumycdn.mehttp://*.mycdn.mehttps://*.mycdn.mehttp://st-ok.cdn-vk.ruhttps://st-ok.cdn-vk.ruhttp://st-ok-pts.cdn-vk.ruhttps://st-ok-pts.cdn-vk.ruwss://ad.mail.ru*.mail.ru*.imgsmail.ru*.mradx.net*.serving-sys.com*.googleapis.com*.gstatic.comwww.google.comhttps://api-maps.yandex.ruyastatic.netyandex.st*.doubleverify.com*.adsafeprotected.comhttps://cdn.consentmanager.nethttps://football.sportmail.ru*.google.ru*.google.com*.googlesyndication.com*.yandex.rustatic.dzeninfra.ruconnect.ok.ruhttps://connect.ok.rublob:
script-src 'unsafe-inline''unsafe-eval'*.mail.ruhttps://*.mail.ru*.imgsmail.ru*.mradx.netok.ru*.ok.ruodnoklassniki.ru*.odnoklassniki.ruokcdn.ruhttp://*.okcdn.ruhttps://*.okcdn.ruhttp://st-ok.cdn-vk.ruhttps://st-ok.cdn-vk.ruhttp://st-ok-pts.cdn-vk.ruhttps://st-ok-pts.cdn-vk.rumycdn.mehttp://*.mycdn.mehttps://*.mycdn.memc.yandex.ruan.yandex.ruyastatic.netyandex.st*.google-analytics.comapi-maps.yandex.ruhttps://api-maps.yandex.ruhttps://clck.yandex.ru*.googleapis.com*.gstatic.comwww.google.comwww.youtube.comhttps://www.youtube.com*.ytimg.comhttps://*.ytimg.com*.doubleverify.com*.dvtps.com*.doubleclick.net*.googletagservices.com*.googlesyndication.com*.googleadservices.com*.goodgame.ruhttps://*.goodgame.ruhttps://*.moatads.com*.adlooxtracking.com*.adlooxtracking.ru*.adsafeprotected.com*.serving-sys.com*.serving-sys.ru*.weborama.fr*.weborama-tech.ruhttps://enterprise.api-maps.yandex.ruhttps://suggest-maps.yandex.ruhttps://*.hit.gemius.plhttps://*.consentmanager.nethttps://gum.criteo.comhttps://football.sportmail.ru*.googletagmanager.comconnect.facebook.net*.google.ru*.google.com*.googlesyndication.comyandex.rustatic.dzeninfra.ru*.adtrafficquality.google
worker-src blob:'self'
connect-src *wss:blob:data:
font-src *data:blob:
frame-src *blob:'self'
img-src *data:blob:about:
media-src *data:blob:
object-src *
report-uri /csp/report
F
Subresource Integrity
Action
0 of 252 external resources have SRI
FIX
0 of 252 external resources have SRI
Warning::
External script from yandex.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //yandex.ru/ads/system/context.js
Warning::
External script from www.google-analytics.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://www.google-analytics.com/analytics.js
Warning::
External script from www.googletagmanager.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://www.googletagmanager.com/gtag/js?id=G-GEGXS3ELM6&cx=c&gtm=4e64f0
Warning::
External script from top-fwz1.mail.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://top-fwz1.mail.ru/js/code.js
Warning::
External script from mc.yandex.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://mc.yandex.ru/metrika/tag.js
Warning::
External script from www.googletagmanager.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://www.googletagmanager.com/gtm.js?id=GTM-WFHQQ63
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/css/ncore_bihfpicx.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/css/colors_gzct653y.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/css/colors.dark_byb9hya0.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/css/login_dmnsraol.css
Warning::
External link from st.okcdn.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://st.okcdn.ru/static/css-hacks/2-0-69/overrides_ix05r5rk.css
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/require-2.1.11_kyyqpj4q.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/tracerPlaceholder_chnrkzcc.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/polyfillsModern_mx8ooaq7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/polyfills_cknco4yg.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/classic_kn88qqh3.js
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/components_e52be599.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_design-system.web.css-11.6.0.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-arrow-button/layer-arrow-button-latest-AEZVYUU3.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-close-button/layer-close-button-latest-EXIEMIRA.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/toolbar-search/toolbar-search-latest-CZUV6X34.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/auth-login_vkid-form-adapter_3f194bba.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-loader/layer-loader-latest-D2DVISMI.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/auth-login-popup/auth-login-popup-latest-UX2TWZDT.css
Warning::
External link from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/bdui-component/bdui-component-latest-55R3652X.css
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/scriptBottom_iw5e6p6z.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/HookActivator_f36d65yb.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/TracerService_bfvsqh5k.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/wld_dk1dp0dn.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/capture_ev6rbtle.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/CurrentUserCfg_k7p24sso.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/pms_h0f9gwo9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/throttle_n5abvd2o.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/StartupTimingLogger_k3a3xijo.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/loggingModules_e89w6yjt.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/theme_j5uun7nc.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/deviceInfo_nmc6oxi7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/OhManager_o1kj9jto.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LayersLoader_nmepckf5.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AccessibleModal_ixpu39yi.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/cookie_n3q7bswl.js
Warning::
External script from limg.imgsmail.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://limg.imgsmail.ru/informers/abp/px.js?ch=1
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/GwtConfig_i86bns5w.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LogClicks_l4ly47iz.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/MobileMenuCheckbox_crvtmd1h.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/NavigationHandler_ehfzm3jn.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/react-loader_jmnvyjbs.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ToastManager_ctwvzic1.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/css-loader_brt9s9j7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/PerformanceTimingLogger_fn5812ln.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/OkWebView_ik62rgt0.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/safe-css-loader_d9qja71r.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/FixedTopBock_jcprji5v.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_NavigationDataProviderHookJs_dk82ko0d.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ToolbarReact_j18zi0uf.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/VkEcosystem_euapty6i.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/cookie__o8nri4yj.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LoadMainContentHandler_jq0dogcm.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/MediascopeTracker_bhirbz3l.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/TimespentTracker_jwg8wl9e.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/RegistrationDesign21_n65rmtei.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Registration_i2fuflw5.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LazyLoadBlock_ea0qf8a8.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ClickLog_dju7bjmu.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_HookJs_eqefemeh.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Link_euc7dcyl.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/SimplePopup_k8yq0644.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/FingerprintJS_bj7ec5o6.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Pushes_lc8zojj9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/DzBlockDetect_ii63s3wl.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/VideoChatPush_f0emz2n7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LoggerCoreHook_matal2de.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/FrameRateLogger_ntfq6pmy.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/MetricsRenderLogger_hizgotx8.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/MetricsAnonymUserBehaviourImitation_iygset6m.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/webapi_iu2p6dgt.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/vanilla_eth599qi.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/react-tag-loader_mrj2arcg.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ThemeEventBuses_bexxkvm9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ThemeEnum_hvzwzn9n.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AjaxNavigationLog_oxmn9133.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/screens_hv6rcwzj.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ReactInitializer_e3n8otcy.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ReactResourceResolver_ear5xq3o.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/JavascriptModuleResolver_bsoxuobt.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/RequireJSModuleResolver_ekle3d99.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/EventBus_hfsxqc6l.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/EventFactoryForEventBus_dakrbzmj.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LayersEventBuses_jn0fuack.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/InternetQuality_f2e08c12.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/a11tyHelper_nc1lb0wc.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/dom_mv57s4cb.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/GwtExperimentsCfg_g93c6dn5.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/StatLogger_muj86wqu.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/utils_bktafvqp.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LogListenerEventBuses_bc0ekf3p.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/WebVitalsLogger_m5fyqmid.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LayoutEventBuses_ieql242w.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ReactLoaderHolder_k82qwkze.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/URLData_ikqtdcu1.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ToastManagerEventBuses_c6g48kh6.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ToolbarSearchEventBuses_fdf6vviv.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/safeJSONParse_maa73nyx.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/events_ety51ftz.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/listeners_h9pqdrg7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ios_j6sgoroa.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/index_jx0kpsyn.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/EventFactory_m7kk3sgv.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/navigation_fth137c4.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/environment_n9tcq4ka.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/tabs_odjuvwib.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/types_kp3ngby9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/index_2lslehyn.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/OKAppMethodsNames_ekhxn1zf.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/run_cstfcurw.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/safeJSONStringify_krf3a6iz.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/debounce_csa0axh1.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/JsonCustomHook_gabojp1z.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/BanDataCfgJs_mpx2mphi.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/utils_l4ocffvt.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/jquery-1.8.3_65hpifcf.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/DispatcherJs_em2y8vwu.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Base_HookJs_nxt41dp1.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_TransportJs_ftkp68te.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_DataNull_butazm2j.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_CfgJs_ohhe2ew9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Application_CfgJs_hfsqajhl.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_MultiloadCfgJs_onnzzfdt.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_RefreshPolicyCfgJs_b20mns8t.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_Common_np1wb555.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/BufferedCommandJs_d7nmvsvp.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_Stat_go70ekp2.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_PlaceListenersProxyJs_i79q08oe.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_PlaceListeners_iv1cfmb5.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/rbUtils_eglv29t4.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ProxyJs_ooxsgblw.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ModelJs_o0kqugui.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_DataText_co9meosr.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ConstantJs_dv2i7mty.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ParamsJs_fqzbd39g.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_ViewJs_g5ash8mj.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/_DataIframe_39xzmy90.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/HtmlRendererJs_mcr7ltg3.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/JSEvaluatorJs_fjgye9bo.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Simple_Js_m47v5gkh.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/DurationJs_cygf3x0e.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ValueProviderJs_n7lteign.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Adf_TransportJs_j9q1zfe9.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/NewsFetchCoordinator_k5efdfyr.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/storage_mfz9olal.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/parseJsonConf_gbyv7krd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/utils_ccc6mbmo.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/YandexMetricService_o6nlpldl.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/MyTrackerService_dczmk2j8.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/Service_kko7yy6s.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/TimespentTrackerService_ei99vq4g.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/TimespentTrackerTypes_h0xnpf70.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/StatesManager_k07uw811.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AuthLoginMainPageEventBuses_c579jfjq.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AuthLoginPopupEventBuses_norc9e6m.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LoggerCore_gqalzy4i.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/DataCache_etxra6zq.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/VideoChatSound_h61diti0.js
Warning::
External script from limg.imgsmail.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://limg.imgsmail.ru/informers/abp/px.js?ch=2
Warning::
External script from ad.mail.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://ad.mail.ru/static/sync-loader.js?v=2
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendors_96c0234e.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/core-client_afa84034.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/components_d1182347.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/pts_jdlyu16y.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/LazyIconsCache_ghfgax8n.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ClientPropertiesEventBuses_fp9ejluh.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/PackageRegistry_klpu9ibn.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/bdui-events-adapter/bdui-events-adapter-latest-UI4MPKLS-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-arrow-button/layer-arrow-button-latest-NZ2UPGQM-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-close-button/layer-close-button-latest-3GQV7EBC-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/layer-loader/layer-loader-latest-KNR6UOBJ-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/auth-login-popup/auth-login-popup-latest-ANIKZOHU-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/bdui-component/bdui-component-latest-DJ7CNJBH-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/toast-manager_5afaa3d7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/auth-login_vkid-form-adapter_efe77212.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/core-LSSVPFQD-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_bdui-renderer-1.8.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/BduiEventBuses_gvnr1h7x.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-18.2.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/mobx-react-6.3.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/classnames-2.5.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_design-system-11.6.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react_jsx-runtime-18.2.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_utils-11.6.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/mobx-4.15.7-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-dom-18.2.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/appInfo_uflhhuog.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/GroupJoinEventBuses_h1mu5aj6.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_core-11.6.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/CommentWidgetsController_oyjux6o3.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/BduiActionsResolver_jmx04kz0.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/resize-observer-polyfill-1.5.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/ImageSensitiveService_bacdiptu.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_hooks-11.6.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/OKVideo_nrc1zz9j.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@ok_common_models-11.6.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vk-ecosystem_skvoznoy-odkl-1.4.2-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/vkconnect_glmuz52u.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/socialSignIn_pfiwz0vx.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/mobx-react-lite-2.2.2-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-dom_client-18.2.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/diff-K2JRIP6Y-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-router-7.11.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/scheduler-0.23.2-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/emoji-regex-10.3.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-imask-7.6.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/motion_react-12.23.24-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/sonner-2.0.1-amd.js
Warning::
External script from st.okcdn.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st.okcdn.ru/static/MegaPlayer/10-12-1/okVideoPlayerUtils.min.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/app_fky7fqri.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/VideoPlayerEventBuses_ft4upj6v.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/getBreakpoint_lnyyl7jd.js
Warning::
External script from st.okcdn.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st.okcdn.ru/static/music/bootstrap.web-1-0-9-1757496654922.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/constants_g72sarzv.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_vkui-7.1.3-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkid_captcha-1.0.3-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AuthLoginPopup_jbk7kihk.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/AuthTypes_dx21h05m.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/socialAuthHandler_lx83nh3v.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/appleSDK_culba4g7.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/framer-motion-12.23.25-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/imask_esm-7.6.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/imask_esm_imask-7.6.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/prop-types-15.8.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/cookie-VNNDEZIT-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/set-cookie-parser-ITOPZTVP-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_vkjs-2.0.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_vkui-floating-ui_core-Y3JZXKU5-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_vkui-floating-ui_utils_dom-7D7HHSCJ-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_icons-2.169.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_vkui-floating-ui_react-dom-6JUIYBXQ-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/date-fns-4.1.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/date-fns_constants-4.1.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/react-is-16.13.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/motion-dom-12.23.23-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@emotion_is-prop-valid-1.4.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/motion-utils-12.23.6-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@floating-ui_utils-0.2.9-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@floating-ui_dom-1.6.13-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/clsx-2.1.1-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@emotion_memoize-0.9.0-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@floating-ui_core-1.6.9-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@floating-ui_utils_dom-0.2.9-amd.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/react/vendor/@vkontakte_icons-sprite-2.3.1-amd.js
Warning::
External script from yastatic.net lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://yastatic.net/safeframe-bundles/0.83/host.js
Warning::
External script from st-ok.cdn-vk.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: //st-ok.cdn-vk.ru/res/js/require-conf-74279e365aaf0d2087cac728fbcdd5a9.js
Warning::
External script from privacy-cs.mail.ru lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://privacy-cs.mail.ru/static/sync-loader.js
SRI Coverage 0 / 252 of external resources have integrity hashes
TagDomainIntegrity
<script>yandex.ru Missing
<script>www.google-analytics.com Missing
<script>www.googletagmanager.com Missing
<script>top-fwz1.mail.ru Missing
<script>mc.yandex.ru Missing
<script>www.googletagmanager.com Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st.okcdn.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<link>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>limg.imgsmail.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>limg.imgsmail.ru Missing
<script>ad.mail.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st.okcdn.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st.okcdn.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>st-ok.cdn-vk.ru Missing
<script>yastatic.net Missing
<script>st-ok.cdn-vk.ru Missing
<script>privacy-cs.mail.ru Missing
D
Permissions-Policy
Action
No header set
FIX
No header set
Warning::
No Permissions-Policy header
Consider adding a Permissions-Policy header to restrict browser feature access from embedded content.

No Permissions-Policy header set.

Without this header, embedded iframes can request access to sensitive device features.

Suggested header
Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), usb=()
C
Security Headers
Action
6 of 10 headers properly configured
REVIEW
6 of 10 headers properly configured
Info::
Strict-Transport-Security is properly configured
Got: max-age=63072000;includeSubdomains;preload
Info::
X-Content-Type-Options is properly configured
Got: nosniff
Info::
X-Frame-Options is properly configured
Got: SAMEORIGIN
Warning::
Referrer-Policy header is missing
Controls how much referrer information is sent with requests. Set to 'strict-origin-when-cross-origin' or stricter.
Expected: strict-origin-when-cross-origin
Warning::
Permissions-Policy header is missing
Controls which browser features (camera, microphone, geolocation) are allowed. Set it to restrict unused features.
Expected: geolocation=(), camera=(), microphone=()
Info::
Content-Security-Policy is present
Got: default-src data: 'self' 'unsafe-inline' 'unsafe-eval' ok.ru *.ok.ru odnoklassni…
Warning::
Cross-Origin-Opener-Policy header is missing
COOP isolates your browsing context, preventing cross-origin side-channel attacks. Set to 'same-origin'.
Expected: same-origin
Warning::
Cross-Origin-Embedder-Policy header is missing
COEP prevents loading cross-origin resources without explicit permission. Required for SharedArrayBuffer and high-resolution timers.
Expected: require-corp
Info::
X-Powered-By header is not present
Info::
Server header is present without version info
Got: kittenx

Controls how much referrer information is sent with requests. Set to 'strict-origin-when-cross-origin' or stricter.

Expected: strict-origin-when-cross-origin
Why this matters

Default browser behavior leaks full URLs (including query params and tokens) to every third-party resource — set a strict policy.

Learn more

Without a Referrer-Policy header, browsers send the full referring URL with images, scripts, and fonts loaded from third-party origins. URLs containing tokens, user IDs, or session params end up in third-party logs. Set `Referrer-Policy: strict-origin-when-cross-origin` (or stricter) to limit leakage.

Source: MDN / W3C

Controls which browser features (camera, microphone, geolocation) are allowed. Set it to restrict unused features.

Expected: geolocation=(), camera=(), microphone=()
Why this matters

Permissions-Policy locks down browser APIs you don't use — without it, every page can request camera/mic/geolocation if XSS lands.

Learn more

By default every page can request the camera, microphone, geolocation, payment APIs, and dozens more. Permissions-Policy turns off the ones you don't need so a future bug can't quietly start using them. It's a defense-in-depth header — one line, big surface reduction.

Source: MDN / W3C

COOP isolates your browsing context, preventing cross-origin side-channel attacks. Set to 'same-origin'.

Expected: same-origin
Why this matters

COOP isolates your top-level browsing context from cross-origin windows — without it, popup-based side-channel attacks remain possible.

Learn more

Cross-Origin-Opener-Policy: same-origin prevents cross-origin pages from sharing a browsing-context group with yours. This blocks cross-window references that enable Spectre-style timing attacks and tab-nabbing. Required if you want to enable SharedArrayBuffer.

Source: MDN / web.dev

COEP prevents loading cross-origin resources without explicit permission. Required for SharedArrayBuffer and high-resolution timers.

Expected: require-corp
Why this matters

COEP enforces that all embedded resources opt-in to cross-origin embedding — required for cross-origin isolation features.

Learn more

Cross-Origin-Embedder-Policy: require-corp ensures every embedded resource (script, iframe, image) explicitly allows being loaded cross-origin. Combined with COOP, this enables the cross-origin-isolated context that unlocks SharedArrayBuffer, high-resolution timers, and other powerful APIs.

Source: MDN / web.dev

C
Cookie Security
Action
4 cookies analyzed, 7 checks passed
REVIEW
4 cookies analyzed, 7 checks passed
Info::
Cookie 'bci' has the Secure flag
Info::
Cookie 'bci' has the HttpOnly flag
Warning::
Cookie 'bci' has no SameSite attribute
Without an explicit SameSite attribute, browser default behavior varies. Set SameSite=Lax or Strict.
Info::
Cookie '_statid' has the Secure flag
Info::
Cookie '_statid' has the HttpOnly flag
Warning::
Cookie '_statid' has no SameSite attribute
Without an explicit SameSite attribute, browser default behavior varies. Set SameSite=Lax or Strict.
Critical::
Cookie 'cookieChoice' is missing the Secure flag
Without the Secure flag, this cookie can be sent over unencrypted HTTP, exposing it to interception.
Warning::
Cookie 'cookieChoice' is missing the HttpOnly flag
Without HttpOnly, this cookie can be accessed by JavaScript, making it vulnerable to XSS-based theft.
Warning::
Cookie 'cookieChoice' has no SameSite attribute
Without an explicit SameSite attribute, browser default behavior varies. Set SameSite=Lax or Strict.
Info::
Cookie 'ss_wb' has the Secure flag
Info::
Cookie 'ss_wb' has the HttpOnly flag
Info::
Cookie 'ss_wb' has SameSite=None
4 cookies analyzed 1 critical 4 warnings
NameSecureHttpOnlySameSiteSizeIssues
bci22 B1
_statid43 B1
cookieChoice12 B3
ss_wbNone104 B
B
CORS Configuration
No CORS headers
REVIEW
No CORS headers
Info::
No CORS headers present — secure default
CORS Configuration Secure

No CORS headers detected.

Cross-origin requests are blocked by browser same-origin policy.

Origin reflection test

Some servers mirror the request Origin header, which can be exploited. Test manually:

curl -sI -H "Origin: https://evil.com" <url> | grep -i access-control
C
Known vulnerability matches
Action
14 known vulnerability match(es) against detected tech
REVIEW

Known Vulnerabilities

LibraryVersionSeveritySummaryFixed In
Bootstrap1-0-9mediumcross-site scripting vulnerability2.1.0
Bootstrap1-0-9mediumIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.3.4.0
Bootstrap1-0-9mediumXSS in data-container property of tooltip3.4.0
Bootstrap1-0-9mediumIn Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.3.4.0
Bootstrap1-0-9mediumXSS in data-target property of scrollspy3.4.0
Bootstrap1-0-9lowBootstrap before 4.0.0 is end-of-life and no longer maintained.3.999.999
jQuery1.8.3mediumSelector interpreted as HTML1.9.0b1
jQuery1.8.3mediumVersions of jquery prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed. This allows attackers to execute arbitrary JavaScript in a victim's browser. ## Recommendation Upgrade to version 1.9.0 or later.1.9.0
jQuery1.8.3medium3rd party CORS request may execute1.12.0
jQuery1.8.3mediumparseHTML() executes scripts in event handlers2.2.0
jQuery1.8.3lowjQuery 1.x and 2.x are End-of-Life and no longer receiving security updates2.999.999
jQuery1.8.3mediumjQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution3.4.0
jQuery1.8.3mediumpassing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.3.5.0
jQuery1.8.3mediumRegex in its jQuery.htmlPrefilter sometimes may introduce XSS3.5.0
B
security.txt
Published with 2 contact(s)
REVIEW

security.txt

Contact: https://bugbounty.standoff365.com/programs/odnoklassniki_vk, https://bugbounty.bi.zone/companies/odnoklassniki/main
Policy: https://ok.ru/.well-known/security.txt
A+
TLS & Certificates
TLS 1.3, 7 checks passed
PASS
TLS 1.3, 7 checks passed
Info::
TLS 1.3 is used
Got: TLS 1.3
Info::
Strong cipher suite is used
Got: TLS_CHACHA20_POLY1305_SHA256
Info::
HTTP/2 is not negotiated
HTTP/2 provides multiplexing and header compression for better performance.
Got: http/1.1
Info::
Certificate is valid (expires in 206 days)
Got: 2026-11-09T06:16:08Z
Info::
Certificate chain has 3 certificates
Info::
Certificate uses modern signature algorithm
Got: SHA256-RSA
Info::
Certificate covers 29 domain(s)
Got: *.ok.ru, odnoklassniki.ru, ok.me, okl.lt, oklive.app, tamtam.chat, tt.me, m.odnoklasniki.ru, m.odnoklasniki.by, m.odnoklasniki.ua, m.odnoklassniki.ru, m.odnoklassniki.by, m.odnoklassniki.tj, m.odnoklassniki.lv, m.odnoklassniki.eu, m.odnoklassniki.am, m.odnoklassniki.co.ee, *.ms.ok.ru, *.odnoklassniki.ru, *.ok.me, *.okl.lt, *.oklive.app, *.tamtam.chat, *.tt.me, *.m.ok.ru, *.dating.ok.ru, *.mscu.ok.ru, ms.ok.ru, ok.ru
Info::
Certificate is issued by a trusted CA
Got: CN=GlobalSign RSA OV SSL CA 2018,O=GlobalSign nv-sa,C=BE

HTTP/2 provides multiplexing and header compression for better performance.

Why this matters

HTTP/1.1 forces the browser to make sequential requests, multiplying latency on every page.

Learn more

HTTP/2 (and HTTP/3) multiplex many requests over a single connection, eliminating head-of-line blocking. HTTP/1.1 forces the browser to either queue requests or open many parallel connections — both worse. Most modern web servers support HTTP/2 with one config line.

Source: MDN Web Docs

Connection
Protocol
TLS 1.3
Cipher Suite
TLS_CHACHA20_POLY1305_SHA256
HTTP Version
HTTP/1.1

Certificate Chain

Leaf Certificate
Subject CN=*.ok.ru,O=VK LLC,L=Moscow,ST=Moscow,C=RUIssuer CN=GlobalSign RSA OV SSL CA 2018,O=GlobalSign nv-sa,C=BEValid 2025-10-10T16:48:01Z → 2026-11-09T06:16:08ZExpires in 206 days SANs *.ok.ru, odnoklassniki.ru, ok.me, okl.lt, oklive.app, tamtam.chat, tt.me, m.odnoklasniki.ru, m.odnoklasniki.by, m.odnoklasniki.ua, m.odnoklassniki.ru, m.odnoklassniki.by, m.odnoklassniki.tj, m.odnoklassniki.lv, m.odnoklassniki.eu, m.odnoklassniki.am, m.odnoklassniki.co.ee, *.ms.ok.ru, *.odnoklassniki.ru, *.ok.me, *.okl.lt, *.oklive.app, *.tamtam.chat, *.tt.me, *.m.ok.ru, *.dating.ok.ru, *.mscu.ok.ru, ms.ok.ru, ok.ruSignature SHA256-RSASerial 2487cdcbfff8abe1bd192f5f
Intermediate (CA Certificate)
Subject CN=GlobalSign RSA OV SSL CA 2018,O=GlobalSign nv-sa,C=BEIssuer CN=GlobalSign,OU=GlobalSign Root CA - R3,O=GlobalSignValid 2018-11-21T00:00:00Z → 2028-11-21T00:00:00ZExpires in 949 days Signature SHA256-RSASerial 1ee5f221dfc623bd4333a8557
Intermediate (CA Certificate)
Subject CN=GlobalSign,OU=GlobalSign Root CA - R3,O=GlobalSignIssuer CN=GlobalSign,OU=GlobalSign Root CA - R3,O=GlobalSignValid 2009-03-18T10:00:00Z → 2029-03-18T10:00:00ZExpires in 1066 days Signature SHA256-RSASerial 4000000000121585308a2
A+
JS Library Vulnerabilities
No known vulnerabilities
PASS
No known vulnerabilities
Info::
No known JavaScript library vulnerabilities detected

No known JavaScript library vulnerabilities detected.

A+
Information Leakage
No exposures
PASS
No exposures
Info::
security.txt is present — good practice
Info::
No sensitive files exposed

No sensitive files exposed — all paths returned 404.

PathStatusCategoryRisk
/.git/HEAD Not foundVersion Control
/.git/config Not foundVersion Control
/.svn/entries Not foundVersion Control
/.env Not foundConfiguration
/.env.local Not foundConfiguration
/.env.production Not foundConfiguration
/wp-config.php Not foundConfiguration
/.htaccess Not foundConfiguration
/phpinfo.php Not foundDebug
/server-status Not foundDebug
/server-info Not foundDebug
/.well-known/security.txt ExposedSecurity PolicyInfo
A+
Email Security
DMARC: reject
PASS
DMARC: reject
Info::
DMARC policy is reject — strongest protection
DMARC
Policy reject — strongest protection Record v=DMARC1;p=reject;rua=mailto:dmarc_rua@corp.mail.ru;fo=1;
A
Transport Security
HTTP/3, HSTS, and TLS version analysis
PASS
HTTP/3, HSTS, and TLS version analysis
Info::
HTTP/3 (QUIC) not advertised
HTTP/3 eliminates head-of-line blocking. If your CDN supports it, consider enabling it.
Info::
HSTS enabled (includeSubDomains, preload)
Info::
HSTS preload enabled
Info::
TLS 1.3 in use (fastest handshake, 1-RTT)
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback