◆QA Engine
← All runs

https://qa-demo.lab980.com

Export JSON
page started 2026-08-02 01:25 UTC · finished 2026-08-02 01:26 UTC · 1 page · 24s scan · status done · #c5b57e655b9742e78d2d75c0fd5f39e3
10 distinct issues Grouped by rule across all scanned pages, worst severity first. Click the severity pills above to filter.
serious security missing-csp 1 page
Missing Content-Security-Policy header
No Content-Security-Policy header was present, leaving the page without a script-injection safety net.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "serious",
    "title": "Missing Content-Security-Policy header",
    "evidence": {
      "header": "content-security-policy",
      "present": false
    }
  }
]
serious security missing-hsts 1 page
Missing Strict-Transport-Security header
This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "serious",
    "title": "Missing Strict-Transport-Security header",
    "evidence": {
      "header": "strict-transport-security",
      "present": false
    }
  }
]
moderate security missing-frame-protection 1 page
Missing clickjacking protection
Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "moderate",
    "title": "Missing clickjacking protection",
    "evidence": {
      "x-frame-options": null,
      "csp_frame_ancestors": false
    }
  }
]
minor security missing-referrer-policy 1 page
Missing Referrer-Policy header
No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "minor",
    "title": "Missing Referrer-Policy header",
    "evidence": {
      "header": "referrer-policy",
      "present": false
    }
  }
]
minor security missing-xcto 1 page
Missing X-Content-Type-Options: nosniff
Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "minor",
    "title": "Missing X-Content-Type-Options: nosniff",
    "evidence": {
      "header": "x-content-type-options",
      "value": null
    }
  }
]
minor security server-version-disclosure 1 page
Server header discloses version information
The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.
Affected pages (1)
  • / nginx/1.24.0 (Ubuntu)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "minor",
    "title": "Server header discloses version information",
    "evidence": {
      "header": "server",
      "value": "nginx/1.24.0 (Ubuntu)"
    }
  }
]
info security missing-permissions-policy 1 page
Missing Permissions-Policy header
No Permissions-Policy header was present to restrict access to powerful browser features.
Affected pages (1)
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "info",
    "title": "Missing Permissions-Policy header",
    "evidence": {
      "header": "permissions-policy",
      "present": false
    }
  }
]
info ux ux/lighthouse/accessibility 1 page
Lighthouse Accessibility score: 1
Lighthouse category 'Accessibility' scored 1 (0-1 scale).
Affected pages (1)
  • / score 1
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "info",
    "title": "Lighthouse Accessibility score: 1",
    "evidence": {
      "category": "accessibility",
      "score": 1
    }
  }
]
info ux ux/lighthouse/best-practices 1 page
Lighthouse Best Practices score: 1
Lighthouse category 'Best Practices' scored 1 (0-1 scale).
Affected pages (1)
  • / score 1
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "info",
    "title": "Lighthouse Best Practices score: 1",
    "evidence": {
      "category": "best-practices",
      "score": 1
    }
  }
]
info ux ux/lighthouse/performance 1 page
Lighthouse Performance score: 1
Lighthouse category 'Performance' scored 1 (0-1 scale).
Affected pages (1)
  • / score 1
Raw evidence (JSON)
[
  {
    "url": "https://qa-demo.lab980.com",
    "severity": "info",
    "title": "Lighthouse Performance score: 1",
    "evidence": {
      "category": "performance",
      "score": 1
    }
  }
]