Paramètres d'affichage

Choisissez un thème pour personnaliser l'apparence du site.

https://carte-verte.beta.gouv.fr

Comment verdir les habitudes de consommation
Copie d'écran de https://carte-verte.beta.gouv.fr

Nmap

Scan Summary :

A

severityservicevulnerability

info

http (port:80)

info

https (port:443)
Consulter le rapport détaillé

Mozilla HTTP observatory

Scan Summary :

D+

ImpactDescriptionDocumentation

-20

Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.

Remove unsafe-inline and data: from script-src, overly broad sources from object-src and script-src, and ensure object-src and script-src are set.

-20

Does not redirect to an HTTPS site.

Documentation for redirection-to-https

-20

Strict-Transport-Security header not implemented.

Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/).

Rapport détaillé

SSL

Scan Summary :

A+


Expiration : 30/09/2025

Rapport détaillé

Scan OWASPenviron 3 heures

riskname

Medium (High)

CSP: script-src unsafe-inline

Medium (High)

CSP: style-src unsafe-inline

Low (High)

Strict-Transport-Security Header Not Set

Low (Low)

Timestamp Disclosure - Unix

Informational (High)

Sec-Fetch-Dest Header is Missing

Informational (High)

Sec-Fetch-Mode Header is Missing

Informational (High)

Sec-Fetch-Site Header is Missing

Informational (High)

Sec-Fetch-User Header is Missing

Informational (Medium)

Base64 Disclosure

Informational (Medium)

Content-Type Header Missing

Informational (Medium)

Non-Storable Content

Informational (Medium)

Storable and Cacheable Content

Informational (Medium)

Storable but Non-Cacheable Content

Informational (Low)

Information Disclosure - Suspicious Comments

Informational (Low)

Re-examine Cache-control Directives

Rapport détaillé

Nuclei4 mois

SéveritéNameMatcher

info

DNS DMARC - Detectdmarc-detect

info

SPF Record - Detectionspf-record-detect

info

DNS TXT Record Detectedtxt-fingerprint

info

CAA Recordcaa-fingerprint

info

MX Record Detectionmx-fingerprint

info

NS Record Detectionnameserver-fingerprint

info

Allowed Options Methodoptions-method

info

XSS-Protection Header - Cross-Site Scriptingxss-deprecated-header

info

HTTP Missing Security Headersstrict-transport-security

info

HTTP Missing Security Headersx-permitted-cross-domain-policies

info

HTTP Missing Security Headersclear-site-data

info

robots.txt endpoint proberrobots-txt-endpoint

info

WAF Detectionapachegeneric

info

Detect SSL Certificate Issuerssl-issuer

info

SSL DNS Namesssl-dns-names

info

TLS Version - Detecttls-version

info

TLS Version - Detecttls-version