Skip to content
https://coinmarketcap.com

Security

· 12 checks — HTTP headers, CSP, TLS handshake, and cookie hygiene rolled into one auditable list.
SCORE
76
GRADE
C
FIX
3
REVIEW
2
PASS
7
INFO
0
Checks
12
7 PASS 2 REVIEW 3 FIX
F
Content Security Policy
Action
3 of 11 CSP checks passed
FIX
3 of 11 CSP checks passed
Info::
Raw CSP policy
Got: frame-ancestors 'self' https://ss.datasconsole.com; worker-src 'self' blob:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.coinmarketcap.com https://cdn.adx.ws https://cdn.cookielaw.org https://cdn4.buysellads.net https://btloader.com https://script.4dex.io https://www.google.com https://*.googlesyndication.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://ep2.adtrafficquality.google https://www.youtube.com https://s3.tradingview.com https://organizer.bizzabo.com https://telegram.org https://staticrecap.cgicgi.io https://3f0fb9bcf568.edge.sdk.awswaf.com https://unpkg.com/vconsole/dist/vconsole.min.js https://browser.sentry-cdn.com https://ajax.googleapis.com/ajax/libs/jquery/ https://www.recaptcha.net/recaptcha/ https://connect.facebook.net https://www.google-analytics.com https://cdn.id5-sync.com https://cdn.jsdelivr.net/npm/prebid-universal-creative@latest/dist/ https://*.adform.net https://*.adsafeprotected.com https://s0.2mdn.net https://www.googletagservices.com https://yastatic.net https://*.doubleverify.com https://cdn.topsrvimp.com/cmpp/ https://static.vidazoo.com https://confiant-integrations.global.ssl.fastly.net https://rt.marphezis.com/static/client.js https://onetag-sys.com https://ib.3lift.com https://*.flashtalking.com https://c.bannerflow.net https://pxdrop.lijit.com https://code.createjs.com https://cdn.lijit.com https://ajs-assets.ftstatic.com https://js.ad-score.com https://*.amxrtb.com https://yandex.ru https://tagan.adlightning.com https://pn.ybp.yahoo.com https://s.update.rubiconproject.com https://*.adnxs.com https://*.gumgum.com https://secure.cdn.fastclick.net https://tags.crwdcntrl.net https://adsdkprod.azureedge.net https://video-outstream.rubiconproject.com https://ced-ns.sascdn.com https://static.yieldmo.com https://rules.quantcount.com https://adrta.com https://secure.quantserve.com https://rumcdn.geoedge.be https://*.bidswitch.net https://choices.truste.com https://ad.doubleclick.net https://warp.media.net https://assets.a-mo.net https://choices.trustarc.com https://*.rendering.sharethrough.com https://infird.com https://cdn.clinch.co https://a.rfihub.com https://sb.scorecardresearch.com https://static-content-1.smadex.com https://displayf-tm.everesttech.net https://lyr.pubmatic.com https://*.1rx.io https://*.amazon-adsystem.com https://*.aps.amazon-adsystem.com https://creatives.smadex.com https://imasdk.googleapis.com https://widgets.outbrain.com https://*.adroll.com https://aam.a47b.com https://c.evidon.com https://ad4m.at https://dsp-media.eskimi.com https://secured-pixel.com https://creative-measurement.quantcount.com https://dsp-creative.demandbase.com https://as.jivox.com https://cdnjs.cloudflare.com/ajax/libs/gsap/ https://s3.amazonaws.com/stackadapt_public/ https://signal-beacon.s-onetag.com https://*.smilewanted.com https://pixel.adsafeprotected.com https://s.update.indexww.com https://assets.smrtb.com https://s.ads.smartadserver.com https://ajs-assets.ftstatic.com/ftUtils.js https://cache-ssl.celtra.com https://s.yimg.com https://warp.trustedstack.com https://nrb.ybp.yahoo.com https://cdn.confiant-integrations.net https://static.googleadsserving.cn https://pghub.io https://playercdn.jivox.com https://static.criteo.net https://cdn.ampproject.org https://metrics.rapidedge.io https://cr.adsappier.com https://pubmatic.bbvms.com https://ads.pubmatic.com https://obs.cheqzone.com https://z.moatads.com https://ad.atdmt.com https://hal9000.redintelligence.net https://res.adx.opera.com https://createjs.com https://*.createjs.com https://adform.net https://smartadserver.com https://*.smartadserver.com https://sascdn.com https://*.sascdn.com https://smilewanted.com https://adnxs.com https://rubiconproject.com https://*.rubiconproject.com https://pubmatic.com https://*.pubmatic.com https://sharethrough.com https://*.sharethrough.com https://lijit.com https://*.lijit.com https://onetag.com https://id5-sync.com https://*.id5-sync.com https://2mdn.net https://*.2mdn.net https://amxrtb.com https://*.a-mo.net https://a-mo.net https://*.omnitagjs.com https://omnitagjs.com https://cdn.doubleverify.com https://*.quantserve.com https://quantserve.com https://*.quantcount.com https://quantcount.com https://flashtalking.com https://adsafeprotected.com https://*.doubleclick.net https://doubleclick.net https://cdn.celtra.com https://mda.axonix.com https://api.adradv.io https://cdn.bluebillywig.com https://cdn.iprom.net https://noas.mtrtb.com https://static.teads.tv https://*.go.sonobi.com https://tm.ad-srv.net
Warning::
default-src directive is missing
default-src provides a fallback for other directives. Set it to restrict default resource loading.
Expected: default-src 'self'
Critical::
'unsafe-inline' found in script source
'unsafe-inline' allows inline <script> tags, defeating CSP against XSS. Remove it and use nonces or hashes instead.
Got: script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.coinmarketcap.com https://cdn.adx.ws https://cdn.cookielaw.org https://cdn4.buysellads.net https://btloader.com https://script.4dex.io https://www.google.com https://*.googlesyndication.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://ep2.adtrafficquality.google https://www.youtube.com https://s3.tradingview.com https://organizer.bizzabo.com https://telegram.org https://staticrecap.cgicgi.io https://3f0fb9bcf568.edge.sdk.awswaf.com https://unpkg.com/vconsole/dist/vconsole.min.js https://browser.sentry-cdn.com https://ajax.googleapis.com/ajax/libs/jquery/ https://www.recaptcha.net/recaptcha/ https://connect.facebook.net https://www.google-analytics.com https://cdn.id5-sync.com https://cdn.jsdelivr.net/npm/prebid-universal-creative@latest/dist/ https://*.adform.net https://*.adsafeprotected.com https://s0.2mdn.net https://www.googletagservices.com https://yastatic.net https://*.doubleverify.com https://cdn.topsrvimp.com/cmpp/ https://static.vidazoo.com https://confiant-integrations.global.ssl.fastly.net https://rt.marphezis.com/static/client.js https://onetag-sys.com https://ib.3lift.com https://*.flashtalking.com https://c.bannerflow.net https://pxdrop.lijit.com https://code.createjs.com https://cdn.lijit.com https://ajs-assets.ftstatic.com https://js.ad-score.com https://*.amxrtb.com https://yandex.ru https://tagan.adlightning.com https://pn.ybp.yahoo.com https://s.update.rubiconproject.com https://*.adnxs.com https://*.gumgum.com https://secure.cdn.fastclick.net https://tags.crwdcntrl.net https://adsdkprod.azureedge.net https://video-outstream.rubiconproject.com https://ced-ns.sascdn.com https://static.yieldmo.com https://rules.quantcount.com https://adrta.com https://secure.quantserve.com https://rumcdn.geoedge.be https://*.bidswitch.net https://choices.truste.com https://ad.doubleclick.net https://warp.media.net https://assets.a-mo.net https://choices.trustarc.com https://*.rendering.sharethrough.com https://infird.com https://cdn.clinch.co https://a.rfihub.com https://sb.scorecardresearch.com https://static-content-1.smadex.com https://displayf-tm.everesttech.net https://lyr.pubmatic.com https://*.1rx.io https://*.amazon-adsystem.com https://*.aps.amazon-adsystem.com https://creatives.smadex.com https://imasdk.googleapis.com https://widgets.outbrain.com https://*.adroll.com https://aam.a47b.com https://c.evidon.com https://ad4m.at https://dsp-media.eskimi.com https://secured-pixel.com https://creative-measurement.quantcount.com https://dsp-creative.demandbase.com https://as.jivox.com https://cdnjs.cloudflare.com/ajax/libs/gsap/ https://s3.amazonaws.com/stackadapt_public/ https://signal-beacon.s-onetag.com https://*.smilewanted.com https://pixel.adsafeprotected.com https://s.update.indexww.com https://assets.smrtb.com https://s.ads.smartadserver.com https://ajs-assets.ftstatic.com/ftUtils.js https://cache-ssl.celtra.com https://s.yimg.com https://warp.trustedstack.com https://nrb.ybp.yahoo.com https://cdn.confiant-integrations.net https://static.googleadsserving.cn https://pghub.io https://playercdn.jivox.com https://static.criteo.net https://cdn.ampproject.org https://metrics.rapidedge.io https://cr.adsappier.com https://pubmatic.bbvms.com https://ads.pubmatic.com https://obs.cheqzone.com https://z.moatads.com https://ad.atdmt.com https://hal9000.redintelligence.net https://res.adx.opera.com https://createjs.com https://*.createjs.com https://adform.net https://smartadserver.com https://*.smartadserver.com https://sascdn.com https://*.sascdn.com https://smilewanted.com https://adnxs.com https://rubiconproject.com https://*.rubiconproject.com https://pubmatic.com https://*.pubmatic.com https://sharethrough.com https://*.sharethrough.com https://lijit.com https://*.lijit.com https://onetag.com https://id5-sync.com https://*.id5-sync.com https://2mdn.net https://*.2mdn.net https://amxrtb.com https://*.a-mo.net https://a-mo.net https://*.omnitagjs.com https://omnitagjs.com https://cdn.doubleverify.com https://*.quantserve.com https://quantserve.com https://*.quantcount.com https://quantcount.com https://flashtalking.com https://adsafeprotected.com https://*.doubleclick.net https://doubleclick.net https://cdn.celtra.com https://mda.axonix.com https://api.adradv.io https://cdn.bluebillywig.com https://cdn.iprom.net https://noas.mtrtb.com https://static.teads.tv https://*.go.sonobi.com https://tm.ad-srv.net
Critical::
'unsafe-eval' found in script source
'unsafe-eval' allows eval() and similar functions, enabling code injection. Remove it.
Got: script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.coinmarketcap.com https://cdn.adx.ws https://cdn.cookielaw.org https://cdn4.buysellads.net https://btloader.com https://script.4dex.io https://www.google.com https://*.googlesyndication.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://ep2.adtrafficquality.google https://www.youtube.com https://s3.tradingview.com https://organizer.bizzabo.com https://telegram.org https://staticrecap.cgicgi.io https://3f0fb9bcf568.edge.sdk.awswaf.com https://unpkg.com/vconsole/dist/vconsole.min.js https://browser.sentry-cdn.com https://ajax.googleapis.com/ajax/libs/jquery/ https://www.recaptcha.net/recaptcha/ https://connect.facebook.net https://www.google-analytics.com https://cdn.id5-sync.com https://cdn.jsdelivr.net/npm/prebid-universal-creative@latest/dist/ https://*.adform.net https://*.adsafeprotected.com https://s0.2mdn.net https://www.googletagservices.com https://yastatic.net https://*.doubleverify.com https://cdn.topsrvimp.com/cmpp/ https://static.vidazoo.com https://confiant-integrations.global.ssl.fastly.net https://rt.marphezis.com/static/client.js https://onetag-sys.com https://ib.3lift.com https://*.flashtalking.com https://c.bannerflow.net https://pxdrop.lijit.com https://code.createjs.com https://cdn.lijit.com https://ajs-assets.ftstatic.com https://js.ad-score.com https://*.amxrtb.com https://yandex.ru https://tagan.adlightning.com https://pn.ybp.yahoo.com https://s.update.rubiconproject.com https://*.adnxs.com https://*.gumgum.com https://secure.cdn.fastclick.net https://tags.crwdcntrl.net https://adsdkprod.azureedge.net https://video-outstream.rubiconproject.com https://ced-ns.sascdn.com https://static.yieldmo.com https://rules.quantcount.com https://adrta.com https://secure.quantserve.com https://rumcdn.geoedge.be https://*.bidswitch.net https://choices.truste.com https://ad.doubleclick.net https://warp.media.net https://assets.a-mo.net https://choices.trustarc.com https://*.rendering.sharethrough.com https://infird.com https://cdn.clinch.co https://a.rfihub.com https://sb.scorecardresearch.com https://static-content-1.smadex.com https://displayf-tm.everesttech.net https://lyr.pubmatic.com https://*.1rx.io https://*.amazon-adsystem.com https://*.aps.amazon-adsystem.com https://creatives.smadex.com https://imasdk.googleapis.com https://widgets.outbrain.com https://*.adroll.com https://aam.a47b.com https://c.evidon.com https://ad4m.at https://dsp-media.eskimi.com https://secured-pixel.com https://creative-measurement.quantcount.com https://dsp-creative.demandbase.com https://as.jivox.com https://cdnjs.cloudflare.com/ajax/libs/gsap/ https://s3.amazonaws.com/stackadapt_public/ https://signal-beacon.s-onetag.com https://*.smilewanted.com https://pixel.adsafeprotected.com https://s.update.indexww.com https://assets.smrtb.com https://s.ads.smartadserver.com https://ajs-assets.ftstatic.com/ftUtils.js https://cache-ssl.celtra.com https://s.yimg.com https://warp.trustedstack.com https://nrb.ybp.yahoo.com https://cdn.confiant-integrations.net https://static.googleadsserving.cn https://pghub.io https://playercdn.jivox.com https://static.criteo.net https://cdn.ampproject.org https://metrics.rapidedge.io https://cr.adsappier.com https://pubmatic.bbvms.com https://ads.pubmatic.com https://obs.cheqzone.com https://z.moatads.com https://ad.atdmt.com https://hal9000.redintelligence.net https://res.adx.opera.com https://createjs.com https://*.createjs.com https://adform.net https://smartadserver.com https://*.smartadserver.com https://sascdn.com https://*.sascdn.com https://smilewanted.com https://adnxs.com https://rubiconproject.com https://*.rubiconproject.com https://pubmatic.com https://*.pubmatic.com https://sharethrough.com https://*.sharethrough.com https://lijit.com https://*.lijit.com https://onetag.com https://id5-sync.com https://*.id5-sync.com https://2mdn.net https://*.2mdn.net https://amxrtb.com https://*.a-mo.net https://a-mo.net https://*.omnitagjs.com https://omnitagjs.com https://cdn.doubleverify.com https://*.quantserve.com https://quantserve.com https://*.quantcount.com https://quantcount.com https://flashtalking.com https://adsafeprotected.com https://*.doubleclick.net https://doubleclick.net https://cdn.celtra.com https://mda.axonix.com https://api.adradv.io https://cdn.bluebillywig.com https://cdn.iprom.net https://noas.mtrtb.com https://static.teads.tv https://*.go.sonobi.com https://tm.ad-srv.net
Info::
No wildcard in script source
Info::
object-src is set to 'none'
Got: object-src 'none'
Warning::
base-uri directive is missing
Without base-uri, attackers can inject a <base> tag to hijack relative URLs. Set it to 'self' or 'none'.
Expected: base-uri 'self'
Info::
frame-ancestors directive is set
Got: frame-ancestors 'self' https://ss.datasconsole.com
Warning::
form-action directive is missing
form-action restricts where forms can submit data, preventing form hijacking.
Expected: form-action 'self'
Info::
upgrade-insecure-requests is not set
This directive upgrades HTTP resources to HTTPS automatically, preventing mixed content.
Expected: upgrade-insecure-requests
Info::
Content-Security-Policy-Report-Only is also set
A report-only policy is active alongside the enforcing policy for monitoring.
Got: frame-ancestors 'self' https://ss.datasconsole.com; worker-src 'self' blob:; object-src 'none'; script-src 'self' 'unsaf…

'unsafe-inline' allows inline <script> tags, defeating CSP against XSS. Remove it and use nonces or hashes instead.

Why this matters

Unsafe value (unsafe-inline, unsafe-eval) in script-src defeats CSP's main protection — XSS injections can execute again.

Learn more

unsafe-inline allows inline <script> tags; unsafe-eval allows eval() and similar. Both are necessary for some legacy code but explicitly dangerous. Migrate to nonces (per-page random tokens) or hashes (per-script SHA-256) instead.

Source: OWASP CSP / MDN

'unsafe-eval' allows eval() and similar functions, enabling code injection. Remove it.

Why this matters

Unsafe value (unsafe-inline, unsafe-eval) in script-src defeats CSP's main protection — XSS injections can execute again.

Learn more

unsafe-inline allows inline <script> tags; unsafe-eval allows eval() and similar. Both are necessary for some legacy code but explicitly dangerous. Migrate to nonces (per-page random tokens) or hashes (per-script SHA-256) instead.

Source: OWASP CSP / MDN

default-src provides a fallback for other directives. Set it to restrict default resource loading.

Expected: default-src 'self'
Why this matters

Security gaps expose your site and users to attacks, eroding trust.

Without base-uri, attackers can inject a <base> tag to hijack relative URLs. Set it to 'self' or 'none'.

Expected: base-uri 'self'
Why this matters

Missing base-uri in CSP leaves a base-tag injection attack path open even on otherwise strict policies.

Learn more

A common omission: developers add CSP for script-src and frame-ancestors but forget base-uri. The result is a CSP that looks strict but lets an attacker rewrite every URL on the page via <base href>. Add `base-uri 'self'` to close the gap.

Source: MDN CSP

form-action restricts where forms can submit data, preventing form hijacking.

Expected: form-action 'self'
Why this matters

Security gaps expose your site and users to attacks, eroding trust.

This directive upgrades HTTP resources to HTTPS automatically, preventing mixed content.

Expected: upgrade-insecure-requests
Why this matters

Without upgrade-insecure-requests, any HTTP subresource link survives as a mixed-content warning instead of auto-upgrading.

Learn more

Adding `upgrade-insecure-requests` to your CSP turns every http:// subresource fetch into https:// at the browser layer. One-line defense against accidental mixed content from legacy links or third-party widgets.

Source: MDN CSP

A report-only policy is active alongside the enforcing policy for monitoring.

Why this matters

Running enforcing + Report-Only in parallel lets you test stricter directives safely before promoting them.

Source: MDN CSP

Parsed Policy

frame-ancestors 'self'https://ss.datasconsole.com
worker-src 'self'blob:
object-src 'none'
script-src 'self''unsafe-inline''unsafe-eval'blob:https://*.coinmarketcap.comhttps://cdn.adx.wshttps://cdn.cookielaw.orghttps://cdn4.buysellads.nethttps://btloader.comhttps://script.4dex.iohttps://www.google.comhttps://*.googlesyndication.comhttps://securepubads.g.doubleclick.nethttps://googleads.g.doubleclick.nethttps://ep2.adtrafficquality.googlehttps://www.youtube.comhttps://s3.tradingview.comhttps://organizer.bizzabo.comhttps://telegram.orghttps://staticrecap.cgicgi.iohttps://3f0fb9bcf568.edge.sdk.awswaf.comhttps://unpkg.com/vconsole/dist/vconsole.min.jshttps://browser.sentry-cdn.comhttps://ajax.googleapis.com/ajax/libs/jquery/https://www.recaptcha.net/recaptcha/https://connect.facebook.nethttps://www.google-analytics.comhttps://cdn.id5-sync.comhttps://cdn.jsdelivr.net/npm/prebid-universal-creative@latest/dist/https://*.adform.nethttps://*.adsafeprotected.comhttps://s0.2mdn.nethttps://www.googletagservices.comhttps://yastatic.nethttps://*.doubleverify.comhttps://cdn.topsrvimp.com/cmpp/https://static.vidazoo.comhttps://confiant-integrations.global.ssl.fastly.nethttps://rt.marphezis.com/static/client.jshttps://onetag-sys.comhttps://ib.3lift.comhttps://*.flashtalking.comhttps://c.bannerflow.nethttps://pxdrop.lijit.comhttps://code.createjs.comhttps://cdn.lijit.comhttps://ajs-assets.ftstatic.comhttps://js.ad-score.comhttps://*.amxrtb.comhttps://yandex.ruhttps://tagan.adlightning.comhttps://pn.ybp.yahoo.comhttps://s.update.rubiconproject.comhttps://*.adnxs.comhttps://*.gumgum.comhttps://secure.cdn.fastclick.nethttps://tags.crwdcntrl.nethttps://adsdkprod.azureedge.nethttps://video-outstream.rubiconproject.comhttps://ced-ns.sascdn.comhttps://static.yieldmo.comhttps://rules.quantcount.comhttps://adrta.comhttps://secure.quantserve.comhttps://rumcdn.geoedge.behttps://*.bidswitch.nethttps://choices.truste.comhttps://ad.doubleclick.nethttps://warp.media.nethttps://assets.a-mo.nethttps://choices.trustarc.comhttps://*.rendering.sharethrough.comhttps://infird.comhttps://cdn.clinch.cohttps://a.rfihub.comhttps://sb.scorecardresearch.comhttps://static-content-1.smadex.comhttps://displayf-tm.everesttech.nethttps://lyr.pubmatic.comhttps://*.1rx.iohttps://*.amazon-adsystem.comhttps://*.aps.amazon-adsystem.comhttps://creatives.smadex.comhttps://imasdk.googleapis.comhttps://widgets.outbrain.comhttps://*.adroll.comhttps://aam.a47b.comhttps://c.evidon.comhttps://ad4m.athttps://dsp-media.eskimi.comhttps://secured-pixel.comhttps://creative-measurement.quantcount.comhttps://dsp-creative.demandbase.comhttps://as.jivox.comhttps://cdnjs.cloudflare.com/ajax/libs/gsap/https://s3.amazonaws.com/stackadapt_public/https://signal-beacon.s-onetag.comhttps://*.smilewanted.comhttps://pixel.adsafeprotected.comhttps://s.update.indexww.comhttps://assets.smrtb.comhttps://s.ads.smartadserver.comhttps://ajs-assets.ftstatic.com/ftUtils.jshttps://cache-ssl.celtra.comhttps://s.yimg.comhttps://warp.trustedstack.comhttps://nrb.ybp.yahoo.comhttps://cdn.confiant-integrations.nethttps://static.googleadsserving.cnhttps://pghub.iohttps://playercdn.jivox.comhttps://static.criteo.nethttps://cdn.ampproject.orghttps://metrics.rapidedge.iohttps://cr.adsappier.comhttps://pubmatic.bbvms.comhttps://ads.pubmatic.comhttps://obs.cheqzone.comhttps://z.moatads.comhttps://ad.atdmt.comhttps://hal9000.redintelligence.nethttps://res.adx.opera.comhttps://createjs.comhttps://*.createjs.comhttps://adform.nethttps://smartadserver.comhttps://*.smartadserver.comhttps://sascdn.comhttps://*.sascdn.comhttps://smilewanted.comhttps://adnxs.comhttps://rubiconproject.comhttps://*.rubiconproject.comhttps://pubmatic.comhttps://*.pubmatic.comhttps://sharethrough.comhttps://*.sharethrough.comhttps://lijit.comhttps://*.lijit.comhttps://onetag.comhttps://id5-sync.comhttps://*.id5-sync.comhttps://2mdn.nethttps://*.2mdn.nethttps://amxrtb.comhttps://*.a-mo.nethttps://a-mo.nethttps://*.omnitagjs.comhttps://omnitagjs.comhttps://cdn.doubleverify.comhttps://*.quantserve.comhttps://quantserve.comhttps://*.quantcount.comhttps://quantcount.comhttps://flashtalking.comhttps://adsafeprotected.comhttps://*.doubleclick.nethttps://doubleclick.nethttps://cdn.celtra.comhttps://mda.axonix.comhttps://api.adradv.iohttps://cdn.bluebillywig.comhttps://cdn.iprom.nethttps://noas.mtrtb.comhttps://static.teads.tvhttps://*.go.sonobi.comhttps://tm.ad-srv.net
F
Subresource Integrity
Action
0 of 81 external resources have SRI
FIX
0 of 81 external resources have SRI
Warning::
External script from 3f0fb9bcf568.edge.sdk.awswaf.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://3f0fb9bcf568.edge.sdk.awswaf.com/3f0fb9bcf568/1d2f2dc6120c/challenge.js
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/static/cloud/styles/ui_v073_pro.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/dfc29bf51f03d6fd.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/eab595605f754051.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/fc05c498eed6d8b7.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/4f561b54ad7fa9f6.css
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/polyfills-42372ed130431b0a.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/78720.59c8c2d34066ce2e.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/webpack-657d4782037bd898.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/framework-459e978afbe50f14.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/main-8de29c4bf0d2668f.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/pages/_app-e4774c3dfa8b4576.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/94a7ad86-d22f4a83c42adcb3.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/8bd53eb9-ef0e3182240e0497.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/58964-577ccb661e4519e2.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/94972-39b195f94e2c9eee.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/44711-c31abbe10fecf62f.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/10423-1d8ee134c82a4af8.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/47935-0767b585244657ad.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/80644-5469c0793c0d2d3f.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/29782-8724524323bde228.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/97680-14a44c702e919d4c.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/61267-80ee1b3a0d822d79.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/1246-dab9e141573f23f4.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/13249-6b57cafffd0a4801.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/67067-4ea573cc9d400880.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/9462-f81b2ac9da097ada.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/96500-b0c2d3a64365d3ef.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/21917-a513d8020b154ad7.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/75927-4ec14976e30007ec.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/87563-1df3426e2e3686fe.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/38365-04dc9b515309715a.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/26226-1c7c5b201ee9e8ac.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/57538-61911a588286a357.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/41612-ba74a92f5ec45b54.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/62663-ab5fed00bc9b610f.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/47580-26dc2aeb47164165.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/92868-f280d5e5c089c8db.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/43708-5923ff48dc82fa9b.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/47560-85439326f14878c6.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/41896-8b9b230de39581da.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/90087-dbca1f3b0aefbed3.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/6626-d3224fd4fc52805c.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/54941-0c1f48858eb9d9ca.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/79730-b1d39afad7540bf5.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/95482-b9a91a4f3be184cf.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/43908-6849d7d2248d7acb.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/814-64b3c314d8e05a27.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/23346-5e1c2dfdb75e5b68.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/20951-02320aef42843315.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/pages/index-641d300d52bbe20e.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/XJxRHMm6CRUvN1kKaZc6K/_buildManifest.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/XJxRHMm6CRUvN1kKaZc6K/_ssgManifest.js
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/0e0f4b99d97f13c2.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/a4c28809bdb5f28b.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/027b059cd9118c5f.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/b15aa8bac5109c88.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/0ef3e9125c79c737.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/6cdd69a9a5a3cb8a.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/9bb38be0485dd93c.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/dfa35fbe47621fe9.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/7ccec4b9b40ec1dc.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/a4f44a3ac41bf6b8.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/b3a43da285ddfb6c.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/93eb33a35b4638a7.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/3974340e8a6fbe73.css
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/static/addetect/ads-prebid.js
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/67ab356e3aac8941.css
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/bfff9f3304f5e283.css
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/47456.b95d58e4c863bc32.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/95464.43a279d1c11f66d2.js
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/0f003c1cfa7547d5.css
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/38926-60f4b6e78d3e9d22.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/77286.666dfd0ee734ee2a.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/25106.27210855b80fc270.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/39634-c246199a88eb57fc.js
Warning::
External link from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/css/bdd6b8647cccbb3a.css
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/11159.41d2b068b0043941.js
Warning::
External script from s2.coinmarketcap.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://s2.coinmarketcap.com/v1/cmc/_next/static/chunks/57792.ebcf1e3b547c54c3.js
Warning::
External script from cdn.cookielaw.org lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
Warning::
External script from pagead2.googlesyndication.com lacks integrity attribute
Without SRI, if this CDN is compromised, attackers could inject malicious code.
Got: https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-5965828471560237
SRI Coverage 0 / 81 of external resources have integrity hashes
TagDomainIntegrity
<script>3f0fb9bcf568.edge.sdk.awswaf.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<link>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>s2.coinmarketcap.com Missing
<script>cdn.cookielaw.org Missing
<script>pagead2.googlesyndication.com Missing
D
security.txt
Action
No /.well-known/security.txt published
FIX

security.txt

No security.txt found at /.well-known/security.txt

C
Permissions-Policy
Action
1 directives, 5 missing
REVIEW
1 directives, 5 missing
Info::
unload=() — blocked for all origins
Info::
camera not restricted
Consider adding camera=() to block camera access from embedded content.
Info::
microphone not restricted
Consider adding microphone=() to block microphone access from embedded content.
Info::
geolocation not restricted
Consider adding geolocation=() to block geolocation access from embedded content.
Info::
payment not restricted
Consider adding payment=() to block payment access from embedded content.
Info::
usb not restricted
Consider adding usb=() to block usb access from embedded content.

Raw Header

unload=()

Feature Permissions

Blocked Self Only Unrestricted Not Set
unload Blocked
camera Not Set
microphone Not Set
geolocation Not Set
payment Not Set
usb Not Set
B
CORS Configuration
No CORS headers
REVIEW
No CORS headers
Info::
No CORS headers present — secure default
CORS Configuration Secure

No CORS headers detected.

Cross-origin requests are blocked by browser same-origin policy.

Origin reflection test

Some servers mirror the request Origin header, which can be exploited. Test manually:

curl -sI -H "Origin: https://evil.com" <url> | grep -i access-control
A
Security Headers
7 of 10 headers properly configured
PASS
7 of 10 headers properly configured
Info::
Strict-Transport-Security is properly configured (consider adding preload)
Got: max-age=31536000; includeSubdomains
Info::
X-Content-Type-Options is properly configured
Got: nosniff
Info::
X-Frame-Options is properly configured
Got: SAMEORIGIN
Warning::
Referrer-Policy has a weak value
Got: origin-when-cross-origin Expected: strict-origin-when-cross-origin
Info::
Permissions-Policy is set
Got: unload=()
Info::
Content-Security-Policy is present
Got: frame-ancestors 'self' https://ss.datasconsole.com; worker-src 'self' blob:; obj…
Info::
Cross-Origin-Opener-Policy is set but not 'same-origin'
Got: same-origin-allow-popups Expected: same-origin
Warning::
Cross-Origin-Embedder-Policy header is missing
COEP prevents loading cross-origin resources without explicit permission. Required for SharedArrayBuffer and high-resolution timers.
Expected: require-corp
Info::
X-Powered-By header is not present
Info::
Server header is present without version info
Got: Tengine
Expected: strict-origin-when-cross-origin
Why this matters

Weak Referrer-Policy values leak full URLs (with query params, tokens, IDs) to every third-party resource on the page.

Learn more

Default referrer behavior shares the full referring URL with images, scripts, and other resources from third-party origins. If your URLs contain tokens, session IDs, or user emails (in query strings or paths), every third-party tracker gets them. Set `Referrer-Policy: strict-origin-when-cross-origin` (or stricter).

Source: MDN Referrer-Policy / W3C

COEP prevents loading cross-origin resources without explicit permission. Required for SharedArrayBuffer and high-resolution timers.

Expected: require-corp
Why this matters

COEP enforces that all embedded resources opt-in to cross-origin embedding — required for cross-origin isolation features.

Learn more

Cross-Origin-Embedder-Policy: require-corp ensures every embedded resource (script, iframe, image) explicitly allows being loaded cross-origin. Combined with COOP, this enables the cross-origin-isolated context that unlocks SharedArrayBuffer, high-resolution timers, and other powerful APIs.

Source: MDN / web.dev

Expected: same-origin
Why this matters

COOP is set to a less-restrictive value (same-origin-allow-popups or unsafe-none) — partial isolation only.

Learn more

COOP: same-origin is the strictest level. same-origin-allow-popups allows authenticated popup windows back to your origin. unsafe-none is the legacy default (effectively off). Pick the strictest level your app's popup flows tolerate.

Source: MDN COOP

A+
TLS & Certificates
TLS 1.3, 7 checks passed
PASS
TLS 1.3, 7 checks passed
Info::
TLS 1.3 is used
Got: TLS 1.3
Info::
Strong cipher suite is used
Got: TLS_AES_128_GCM_SHA256
Info::
HTTP/2 is not negotiated
HTTP/2 provides multiplexing and header compression for better performance.
Got: http/1.1
Info::
Certificate is valid (expires in 128 days)
Got: 2026-08-27T23:59:59Z
Info::
Certificate chain has 3 certificates
Info::
Certificate uses modern signature algorithm
Got: SHA256-RSA
Info::
Certificate covers 7 domain(s)
Got: coinmarketcap.com, cmc.ai, *.coinmarketcap.com, *.beta.coinmarketcap.com, *.staging.coinmarketcap.com, *.cmc.ai, *.cmcap.io
Info::
Certificate is issued by a trusted CA
Got: CN=Amazon RSA 2048 M02,O=Amazon,C=US

HTTP/2 provides multiplexing and header compression for better performance.

Why this matters

HTTP/1.1 forces the browser to make sequential requests, multiplying latency on every page.

Learn more

HTTP/2 (and HTTP/3) multiplex many requests over a single connection, eliminating head-of-line blocking. HTTP/1.1 forces the browser to either queue requests or open many parallel connections — both worse. Most modern web servers support HTTP/2 with one config line.

Source: MDN Web Docs

Connection
Protocol
TLS 1.3
Cipher Suite
TLS_AES_128_GCM_SHA256
HTTP Version
HTTP/1.1

Certificate Chain

Leaf Certificate
Subject CN=coinmarketcap.comIssuer CN=Amazon RSA 2048 M02,O=Amazon,C=USValid 2025-07-29T00:00:00Z → 2026-08-27T23:59:59ZExpires in 128 days SANs coinmarketcap.com, cmc.ai, *.coinmarketcap.com, *.beta.coinmarketcap.com, *.staging.coinmarketcap.com, *.cmc.ai, *.cmcap.ioSignature SHA256-RSASerial 63740a778196cbe2da1f28b6416ddeb
Intermediate (CA Certificate)
Subject CN=Amazon RSA 2048 M02,O=Amazon,C=USIssuer CN=Amazon Root CA 1,O=Amazon,C=USValid 2022-08-23T22:25:30Z → 2030-08-23T22:25:30ZExpires in 1585 days Signature SHA256-RSASerial 773124a4bcbd44ec7b53beaf194842d3a0fa1
Intermediate (CA Certificate)
Subject CN=Amazon Root CA 1,O=Amazon,C=USIssuer CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=USValid 2015-05-25T12:00:00Z → 2037-12-31T01:00:00ZExpires in 4271 days Signature SHA256-RSASerial 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6
A+
Cookie Security
No cookies set — no cookie security risks
PASS
No cookies set — no cookie security risks
Info::
No cookies set — no cookie security risks

No cookies detected — no cookie security risks to report.

A+
JS Library Vulnerabilities
No known vulnerabilities
PASS
No known vulnerabilities
Info::
No known JavaScript library vulnerabilities detected

No known JavaScript library vulnerabilities detected.

A+
Information Leakage
No exposures
PASS
No exposures
Info::
No security.txt found
Consider adding a security.txt at /.well-known/security.txt.
Info::
No sensitive files exposed

No sensitive files exposed — all paths returned 404.

PathStatusCategoryRisk
/.git/HEAD Not foundVersion Control
/.git/config Not foundVersion Control
/.svn/entries Not foundVersion Control
/.env Not foundConfiguration
/.env.local Not foundConfiguration
/.env.production Not foundConfiguration
/wp-config.php Not foundConfiguration
/.htaccess Not foundConfiguration
/phpinfo.php Not foundDebug
/server-status Not foundDebug
/server-info Not foundDebug
/.well-known/security.txt Not foundSecurity Policy
A+
Email Security
DMARC: reject
PASS
DMARC: reject
Info::
DMARC policy is reject — strongest protection
DMARC
Policy reject — strongest protection Record v=DMARC1;p=reject;sp=reject;pct=100;rua=mailto:david.k@coinmarketcap.com;ruf=mailto:david.k@coinmarketcap.com;ri=86400;aspf=s;adkim=s;fo=1
A
Transport Security
HTTP/3, HSTS, and TLS version analysis
PASS
HTTP/3, HSTS, and TLS version analysis
Info::
HTTP/3 (QUIC) not advertised
HTTP/3 eliminates head-of-line blocking. If your CDN supports it, consider enabling it.
Info::
HSTS enabled (includeSubDomains)
Info::
TLS 1.3 in use (fastest handshake, 1-RTT)
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback