Anna.info website technical test: Difference between revisions

From annawiki
(22 intermediate revisions by the same user not shown)
Line 1: Line 1:
==Links==
==Links==
*https://www.ssllabs.com/ssltest/analyze.html?d=anna.info&latest
*https://www.ssllabs.com/ssltest/analyze.html?d=anna.info
** A (100,95,90,90); This site works only in browsers with SNI support.
** A+ (Certificate 100, Protocal Support 100, Key Exchange 100, Cipher Strength 100)
*https://hstspreload.appspot.com/?domain=anna.info  
** This site works only in browsers with SNI support.
** Status: anna.info is not preloaded.
*https://tls.imirhil.fr/https/anna.info
*https://observatory.mozilla.org/analyze.html?host=anna.info&third-party=false
** A (Protocol 100, Key exchange 100, Cipher 100, Overall 100.0)
** B; Score: Score: 75/100, Tests Passed: 9/10
*https://securityheaders.io/?followRedirects=on&hide=on&q=anna.info
** A
*[[Test by hstspreload.appspot.com]] https://hstspreload.org/?domain=anna.info
** Status: anna.info is currently preloaded.
*https://observatory.mozilla.org/analyze.html?host=anna.info
** A+; Score: 125/100, Tests Passed: 11/11
** Note: One can get a score higher than 100, e.g.
*** Content Security Policy
**** +10 Content Security Policy (CSP) implemented with default-src 'none' and no 'unsafe'
**** +5 Content Security Policy - if no unsafe-inline is present, anna.info having "Content Security Policy (CSP) implemented with 'unsafe-inline' inside style-src" gets 0 for "Content Security Policy"
*** HTTP Strict Transport Security +5 Preloaded via the HTTP Strict Transport Security (HSTS) preloading process
*** Referrer Policy +5 Referrer-Policy header set to "no-referrer", "same-origin", "strict-origin" or "strict-origin-when-cross-origin"
*** X-Frame-Options +5 X-Frame-Options (XFO) implemented via the CSP frame-ancestors directive
*https://www.google.com/webmasters/tools/mobile-friendly/?url=https%3A%2F%2Fanna.info%2F
*https://www.google.com/webmasters/tools/mobile-friendly/?url=https%3A%2F%2Fanna.info%2F
**Awesome! This page is mobile-friendly.
**Page is mobile-friendly | This page is easy to use on a mobile device
*https://developers.google.com/speed/pagespeed/insights/?url=https%3A%2F%2Fanna.info%2F
*https://developers.google.com/speed/pagespeed/insights/?url=https%3A%2F%2Fanna.info%2F
**mobile 100 / 100 Speed, 100 / 100 User Experience; desktop 100 / 100 Suggestions Summary
**mobile 80 / 100
**desktop 97 / 100


==hstspreload.appspot.com==
==Issues==
  Error: No HSTS header
  Content-Security-Policy default-src 'self'; style-src 'self' 'unsafe-inline'
Response error: No HSTS header is present on the response.
The "style-src 'unsafe-inline'" prevents getting +5 points. Inline CSS is used
*for getting 100/100 on Goolge speed test, which does not seem to be possible with external CSS
*to to CSS marking in MediaWiki, e.g. cells in tables


Error: Too many redirects
==Other==
There are more than 3 redirects starting from `http://anna.info`.
*https://www.heise.de/forum/heise-online/News-Kommentare/heise-online-HTTPS-auch-fuer-Mobilgeraete/X-XSS-Protection-X-Content-Type-Options-Content-Security-Policy-nicht-vergessen/posting-29747747/show/
 
Error: Insecure redirect
`http://anna.info` redirects to an insecure page on redirect #3: `http://anna.info/wiki/Main_Page`
 
Error: Insecure redirect
`https://anna.info` redirects to an insecure page on redirect #2: `http://anna.info/wiki/Main_Page`
 
Error: www subdomain does not support HTTPS
Domain error: The www subdomain exists, but we couldn't connect to it using HTTPS
("x509: certificate is valid for tango.info, www.tango.info, not www.anna.info").
Since many people type this by habit, HSTS preloading would likely cause issues for your site.
---
Error: www subdomain does not support HTTPS
Domain error: The www subdomain exists, but we couldn't connect to it using HTTPS
("x509: certificate is valid for anna.info, not www.anna.info").
Since many people type this by habit, HSTS preloading would likely cause issues for your site.

Revision as of 2018-02-20T18:44:33

Links

Issues

Content-Security-Policy	default-src 'self'; style-src 'self' 'unsafe-inline'

The "style-src 'unsafe-inline'" prevents getting +5 points. Inline CSS is used

  • for getting 100/100 on Goolge speed test, which does not seem to be possible with external CSS
  • to to CSS marking in MediaWiki, e.g. cells in tables

Other