Security report for wafcybersecurity.com
Free passive scan · WAF/CDN, security headers, TLS, server exposure
F
wafcybersecurity.com
Security score 39/100 · Edge: AWS CloudFront
What we found
Missing HSTSMedium
The HSTS response header is not set.
Missing Content-Security-PolicyMedium
The Content-Security-Policy response header is not set.
Missing X-Frame-OptionsMedium
The X-Frame-Options response header is not set.
Missing X-Content-Type-OptionsLow
The X-Content-Type-Options response header is not set.
Missing Referrer-PolicyLow
The Referrer-Policy response header is not set.
Missing Permissions-PolicyLow
The Permissions-Policy response header is not set.
Server version disclosedLow
The Server header reveals "Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.3.22", helping attackers target known CVEs.
End-of-life softwareHigh
The origin appears to run an end-of-life Apache build, which no longer receives security patches.
✓ Edge protection detected (AWS CloudFront)
wafcybersecurity.com has end-of-life server software and 6 missing security headers — all of which a managed AWS WAF would close.
Protect wafcybersecurity.com — $150/mo, fully managedWant your own report? Scan your site free →