'humble' (HTTP Headers Analyzer)
https://github.com/rfc-st/humble | v.2026-06-13


[0. Info]
 Date : 2026/06/13 - 18:39:15
 URL   : https://en.wikipedia.org
File : humble_https_en.wikipedia.org_20260613_183915_en.html
[1. Enabled HTTP Security Headers]
 Cache-Control: private, s-maxage=0, max-age=0, must-revalidate, no-transform
Content-Security-Policy: script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org mediawiki.org wikimedia.org *.wmflabs.org *.wmcloud.org *.toolforge.org wss://*.toolforge.org *.jsdelivr.net unpkg.com cdnjs.cloudflare.com raw.githubusercontent.com *.github.com code.jquery.com cdn.mathjax.org use.typekit.net fonts.cdnfonts.com use.fontawesome.com i.ytimg.com rsms.me doi.org localhost https://localhost:* http://localhost:* wss://localhost:* ws://localhost:* *.google.com *.gstatic.com *.googleapis.com *.translate.yandex.net yastatic.net ya.ru radically.github.io cdn.sammdot.ca cdn.fontshare.com viaf.org publicai-proxy.alaexis.workers.dev iiif.archive.org api.flickr.com live.staticflickr.com api.anthropic.com api.openai.com api.publicai.co catalogo.pusc.it parsifal.urbe.it opac.sbn.it overpass-api.de api.openrouteservice.org archive.org *.openstreetmap.org *.waymarkedtrails.org *.thunderforest.com registry.ipe.wiki analytics.ipe.wiki qlever.dev app.goacoustic.com wikipedia-archive.ourworldindata.org api.inaturalist.org inaturalist-open-data.s3.amazonaws.com validator.w3.org db.onlinewebfonts.com fontlibrary.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org mediawiki.org wikimedia.org *.wmflabs.org *.wmcloud.org *.toolforge.org wss://*.toolforge.org *.jsdelivr.net unpkg.com cdnjs.cloudflare.com raw.githubusercontent.com *.github.com code.jquery.com cdn.mathjax.org use.typekit.net fonts.cdnfonts.com use.fontawesome.com i.ytimg.com rsms.me doi.org localhost https://localhost:* http://localhost:* wss://localhost:* ws://localhost:* *.google.com *.gstatic.com *.googleapis.com *.translate.yandex.net yastatic.net ya.ru radically.github.io cdn.sammdot.ca cdn.fontshare.com viaf.org publicai-proxy.alaexis.workers.dev iiif.archive.org api.flickr.com live.staticflickr.com api.anthropic.com api.openai.com api.publicai.co catalogo.pusc.it parsifal.urbe.it opac.sbn.it overpass-api.de api.openrouteservice.org archive.org *.openstreetmap.org *.waymarkedtrails.org *.thunderforest.com registry.ipe.wiki analytics.ipe.wiki qlever.dev app.goacoustic.com wikipedia-archive.ourworldindata.org api.inaturalist.org inaturalist-open-data.s3.amazonaws.com validator.w3.org db.onlinewebfonts.com fontlibrary.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org mediawiki.org wikimedia.org *.wmflabs.org *.wmcloud.org *.toolforge.org wss://*.toolforge.org *.jsdelivr.net unpkg.com cdnjs.cloudflare.com raw.githubusercontent.com *.github.com code.jquery.com cdn.mathjax.org use.typekit.net fonts.cdnfonts.com use.fontawesome.com i.ytimg.com rsms.me doi.org localhost https://localhost:* http://localhost:* wss://localhost:* ws://localhost:* *.google.com *.gstatic.com *.googleapis.com *.translate.yandex.net yastatic.net ya.ru radically.github.io cdn.sammdot.ca cdn.fontshare.com viaf.org publicai-proxy.alaexis.workers.dev iiif.archive.org api.flickr.com live.staticflickr.com api.anthropic.com api.openai.com api.publicai.co catalogo.pusc.it parsifal.urbe.it opac.sbn.it overpass-api.de api.openrouteservice.org archive.org *.openstreetmap.org *.waymarkedtrails.org *.thunderforest.com registry.ipe.wiki analytics.ipe.wiki qlever.dev app.goacoustic.com wikipedia-archive.ourworldindata.org api.inaturalist.org inaturalist-open-data.s3.amazonaws.com validator.w3.org db.onlinewebfonts.com fontlibrary.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json; report-to csp-report-to-endpoint
Content-Type: text/html; charset=UTF-8
(*) Nel: { "report_to": "wm_nel", "max_age": 604800, "failure_fraction": 0.05, "success_fraction": 0.0}
Report-To: { "group": "wm_nel", "max_age": 604800, "endpoints": [{ "url": "https://intake-logging.wikimedia.org/v1/events?stream=w3c.reportingapi.network_error&schema_uri=/w3c/reportingapi/network_error/1.0.0" }] }
Reporting-Endpoints: csp-report-to-endpoint='/w/api.php?action=cspreport&format=json';
Server-Timing: cache;desc="hit-front", host;desc="cp6011"
Set-Cookie: WMF-DP=24f;Path=/;HttpOnly;secure;Expires=Sun, 14 Jun 2026 00:00:00 GMT, WMF-Uniq=jLWAGB9Ulfsg4VyqZZlncwN-AAEBAFvd7YUnOS8WqKyQqfRcqAxKsxwzd6fOYt7P;Domain=.wikipedia.org;Path=/;HttpOnly;secure;SameSite=None;Expires=Sun, 13 Jun 2027 00:00:00 GMT
Strict-Transport-Security: max-age=106384710; includeSubDomains; preload
X-Content-Type-Options: nosniff
[2. Missing HTTP Security Headers]
 Clear-Site-Data
 Clears browsing data (cookies, storage, cache) associated with the requesting website.
 Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Clear-Site-Data
Cross-Origin-Embedder-Policy Prevents documents and workers from loading non-same-origin requests unless allowed. Ref: https://mdn.io/Cross-Origin-Embedder-Policy
Cross-Origin-Opener-Policy Prevent other websites from gaining arbitrary window references to a page. Ref: https://mdn.io/Cross-Origin-Opener-Policy
Cross-Origin-Resource-Policy Protect servers against certain cross-origin or cross-site embedding of the returned source. Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Cross-Origin_Resource_Policy
Integrity-Policy Blocks certain resource types without Subresource Integrity metadata. Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Integrity-Policy
(*) Permissions-Policy Previously called "Feature-Policy", allow and deny the use of browser features. Ref: https://scotthelme.co.uk/goodbye-feature-policy-and-hello-permissions-policy/
Referrer-Policy Controls how much referrer information should be included with requests. Ref: https://scotthelme.co.uk/a-new-security-header-referrer-policy/
X-Permitted-Cross-Domain-Policies Limit which data external resources (e.g. Adobe Flash/PDF documents), can access on the domain. Ref: https://github.com/OWASP/www-project-secure-headers/blob/68ad3d2690ab7c5f3c3377bf5b6a3a9d0e0f1d67/mainsite/01_headers.md
X-Frame-Options Prevents clickjacking attacks, limiting sources of embedded content. Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options
[3. Fingerprint HTTP Response Headers]
 These headers can expose IPs, hostnames, software or their versions:

 Server (Generic HTTP Server/Content Delivery Network)
 Value: 'mw-web.eqiad.main-7f7c6f94bc-l4lt2'

[4. Deprecated HTTP Response Headers/Protocols and Insecure Values]
 The following headers/protocols are deprecated or their values may be considered unsafe:

 Cache-Control (Recommended Values)
 Enable 'no-cache' and 'no-store' if there are sensitive data in the URL analyzed.
 Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control
Content-Security-Policy (Deprecated Directives) Avoid deprecated or ignored directives: 'report-uri' Ref: https://content-security-policy.com/
Ref: https://centralcsp.com/docs/csp-directives
Ref: https://developer.mozilla.org/es/docs/Web/HTTP/Reference/Headers/Content-Security-Policy
Content-Security-Policy ('base-uri' Directive Missing) Prevents base URL tampering and redirects to harmful endpoints; try to set it to 'self'. Ref: https://centralcsp.com/docs/base-uri
Content-Security-Policy ('child-src' Directive Missing) Prevents malicious code execution through workers/frames; try to set it to 'self'. Ref: https://centralcsp.com/docs/child-src
Content-Security-Policy ('connect-src' Directive Missing) Protects against unauthorized data exfiltration; try to set it to 'self'. Ref: https://centralcsp.com/docs/connect-src
Content-Security-Policy ('font-src' Directive Missing) Prevents loading malicious web fonts; try to set it to 'self'. Ref: https://centralcsp.com/docs/font-src
Content-Security-Policy ('form-action' Directive Missing) Prevents Cross-Site Request Forgery attacks; try to set it to 'self'. Ref: https://centralcsp.com/docs/form-action
Content-Security-Policy ('frame-ancestors' Directive Missing) Prevents clickjacking attacks; try to set it to 'none'. You can ignore this warning if the 'X-Frame-Options' HTTP header is enabled. Ref: https://centralcsp.com/docs/frame-ancestors
Ref: https://www.w3.org/TR/CSP3/#frame-ancestors-and-frame-options
Content-Security-Policy ('img-src' Directive Missing) Prevents image-based attacks; try to set it to 'self'. Ref: https://centralcsp.com/docs/img-src
(*) Content-Security-Policy ('require-trusted-types-for' Directive Missing) Prevents DOM XSS injection in scripts; try to set it to 'script'. Ref: https://content-security-policy.com/require-trusted-types-for/
(*) Content-Security-Policy ('trusted-types' Directive Missing) Prevents XSS attacks; try to set it to 'none' or a secure policy. Ref: https://centralcsp.com/docs/trusted-types
Content-Security-Policy ('worker-src' Directive Missing) Prevents unauthorized worker scripts from being loaded; try to set it to 'self'. Ref: https://centralcsp.com/docs/worker-src
Content-Security-Policy (Too Permissive Sources) Review the directives 'default-src', 'script-src', 'style-src'. And limit permissive sources: 'blob:', 'data:' Ref: https://content-security-policy.com/
Content-Security-Policy (Insecure Schemes) Review the directives 'default-src', 'script-src', 'style-src'. And do not allow insecure, unencrypted schemes: 'http:', 'ws:' Ref: https://http.dev/wss
Ref: https://www.cloudflare.com/learning/ssl/why-is-http-not-secure/
Content-Security-Policy (Unsafe Eval) Review the directive 'script-src'. The value 'unsafe-eval' increases the risk of Cross-site Scripting (XSS). Use the value 'wasm-unsafe-eval' instead if you only need WebAssembly, or remove functions that evaluate code from strings, such as eval(). Ref: https://mdn.io/eval
Ref: https://mdn.io/script-src
Content-Security-Policy (Unsafe Inline) Review the directives 'script-src', 'style-src'. The value 'unsafe-inline' increases the risk of Cross-site scripting (XSS). Remove it, and use hashes or nonces instead. Ref: https://content-security-policy.com/hash/
Ref: https://content-security-policy.com/nonce/
Ref: https://csper.io/blog/no-more-unsafe-inline
Report-To (Deprecated Header) This header is deprecated. Use instead "Reporting-Endpoints". Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Report-To
Server-Timing (Potentially Unsafe Header) This header should not expose sensitive application or infrastructure information. Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Server-Timing
Vary (Potentially Unsafe Header) The values of this header may expose others, facilitating attacks if user input is accepted. Ref: https://www.yeswehack.com/fr/learn-bug-bounty/http-header-exploitation
Ref: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Vary
[5. Empty HTTP Response Headers Values]
 Empty HTTP headers (and are therefore considered disabled):

 Accept-Ch
 X-Analytics

[6. Browser Compatibility for Enabled HTTP Security Headers]
 Cache-Control: https://caniuse.com/?search=Cache-Control
Content-Security-Policy: https://caniuse.com/?search=contentsecuritypolicy2
Content-Type: https://caniuse.com/?search=Content-Type
NEL: https://caniuse.com/?search=NEL
Report-To: https://caniuse.com/?search=Report-To
Reporting-Endpoints: https://caniuse.com/?search=Reporting-Endpoints
Server-Timing: https://caniuse.com/?search=Server-Timing
Set-Cookie: https://caniuse.com/?search=Set-Cookie
Strict-Transport-Security: https://caniuse.com/?search=Strict-Transport-Security
Vary: https://caniuse.com/?search=Vary
X-Content-Type-Options: https://caniuse.com/?search=X-Content-Type-Options
[7. Analysis Results]
 Done in 0.2 seconds! (changes with respect to the last analysis in parentheses)

 Enabled headers:              10 (First Analysis)

 Missing headers:               9 (First Analysis)
 Fingerprint headers:           1 (First Analysis)
 Deprecated/Insecure headers:  19 (First Analysis)
 Empty headers:                 2 (First Analysis)
 Findings to review:           31 (First Analysis)

 Analysis Grade:               D (Review 'Deprecated/Insecure headers')

 '(*)' meaning:                Experimental HTTP response directive or header
 '(*)' ref:                    https://mdn.io/Experimental_deprecated_obsolete
'(Not available)' meaning: The history file, analysis_h.txt, could not be accessed