Security report for cityofowensboro.com

Free passive scan · WAF/CDN, security headers, TLS, server exposure

F
cityofowensboro.com
Security score 0/100 · No shield detected · 6 missing security headers
What we found
No WAF or CDN detectedHigh
The origin appears directly exposed — no edge firewall filtering OWASP Top 10 attacks, bad bots, or malicious IPs.
No working HTTPSHigh
The site did not serve over HTTPS — traffic may be unencrypted.
Missing HSTSMedium
The HSTS response header is not set.
Missing Content-Security-PolicyMedium
The Content-Security-Policy response header is not set.
Missing X-Frame-OptionsMedium
The X-Frame-Options response header is not set.
Missing X-Content-Type-OptionsLow
The X-Content-Type-Options response header is not set.
Missing Referrer-PolicyLow
The Referrer-Policy response header is not set.
Missing Permissions-PolicyLow
The Permissions-Policy response header is not set.
Server version disclosedLow
The Server header reveals "ip-10-123-124-184.ec2.internal", helping attackers target known CVEs.

cityofowensboro.com has no WAF/CDN in front of it, 6 missing security headers and a TLS certificate issue — a managed shield can close those (headers via a response-headers policy, not WAF rules).

Protect cityofowensboro.com — $150/mo, fully managed

Want your own report? Scan your site free →