{
 "host": "www.mozmurray.co.uk",
 "scan": {
  "id": 124615877,
  "details_url": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.mozmurray.co.uk",
  "algorithm_version": 6,
  "scanned_at": "2026-09-30T18:42:27.927Z",
  "error": null,
  "grade": "B",
  "score": 70,
  "status_code": 200,
  "tests_failed": 2,
  "tests_passed": 10,
  "tests_quantity": 12
 },
 "detail": {
  "history": [
   {
    "id": 124614292,
    "scanned_at": "2026-09-30T18:32:51.304Z",
    "grade": "B",
    "score": 70
   }
  ],
  "scan": {
   "id": 124615877,
   "algorithm_version": 6,
   "scanned_at": "2026-09-30T18:42:27.927Z",
   "error": null,
   "grade": "B",
   "response_headers": {
    "date": "Wed, 30 Sep 2026 18:42:28 GMT",
    "link": "<https://www.mozmurray.co.uk/wp-json/>; rel=\"https://api.w.org/\", <https://www.mozmurray.co.uk/wp-json/wp/v2/pages/65>; rel=\"alternate\"; title=\"JSON\"; type=\"application/json\", <https://www.mozmurray.co.uk/>; rel=shortlink",
    "vary": "Accept-Encoding",
    "server": "Prometheus",
    "alt-svc": "h3=\":443\"; ma=86400",
    "connection": "close",
    "content-type": "text/html; charset=UTF-8",
    "cache-control": "public, no-cache",
    "referrer-policy": "strict-origin-when-cross-origin",
    "x-frame-options": "SAMEORIGIN",
    "x-xss-protection": "1; mode=block",
    "transfer-encoding": "chunked",
    "pre-cognitive-push": "Enabled",
    "x-grid-srcache-ttl": "2592000",
    "x-grid-srcache-fetch": "HIT",
    "x-grid-srcache-store": "BYPASS",
    "quantum-flux-capacity": "Omega",
    "x-content-type-options": "nosniff",
    "strict-transport-security": "max-age=31536000"
   },
   "score": 70,
   "status_code": 200,
   "tests_failed": 2,
   "tests_passed": 10,
   "tests_quantity": 12
  },
  "tests": {
   "content-security-policy": {
    "expectation": "csp-implemented-with-no-unsafe",
    "name": "content-security-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CSP",
    "title": "Content Security Policy (CSP)",
    "pass": false,
    "result": "csp-not-implemented",
    "score_description": "<p>\n      Content Security Policy (CSP) header not implemented\n      </p>",
    "recommendation": "<p>\n      Implement one, see <a href=\"/en-US/docs/Web/HTTP/Guides/CSP\">MDN's Content Security Policy (CSP) documentation</a>.\n      </p>",
    "score_modifier": -25,
    "data": null,
    "http": false,
    "meta": false,
    "policy": null,
    "num_policies": 0
   },
   "cookies": {
    "expectation": "cookies-secure-with-httponly-sessions",
    "name": "cookies",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/Cookies",
    "title": "Cookies",
    "pass": null,
    "result": "cookies-not-found",
    "score_description": "<p>\n      No cookies detected\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": null,
    "same_site": false
   },
   "cross-origin-embedder-policy": {
    "expectation": "coep-not-implemented",
    "name": "cross-origin-embedder-policy",
    "link": "/en-US/docs/Web/HTTP/Reference/Headers/Cross-Origin-Embedder-Policy",
    "title": "Cross Origin Embedder Policy",
    "pass": true,
    "result": "coep-not-implemented",
    "score_description": "<p>\n      <code>Cross-Origin-Embedder-Policy</code> header not implemented.\n      </p>",
    "recommendation": "<p>\n      Set to <code>require-corp</code> or <code>credentialless</code>.\n      </p>",
    "score_modifier": 0,
    "data": null,
    "http": false
   },
   "cross-origin-opener-policy": {
    "expectation": "coop-not-implemented",
    "name": "cross-origin-opener-policy",
    "link": "/en-US/docs/Web/HTTP/Reference/Headers/Cross-Origin-Opener-Policy",
    "title": "Cross Origin Opener Policy",
    "pass": true,
    "result": "coop-not-implemented",
    "score_description": "<p>\n      <code>Cross-Origin-Opener-Policy</code> header not implemented.\n      </p>",
    "recommendation": "<p>\n      Set to <code>same-origin</code>, <code>same-origin-allow-popups</code>, or <code>noopener-allow-popups</code>.\n      </p>",
    "score_modifier": 0,
    "data": null,
    "http": false
   },
   "cross-origin-resource-sharing": {
    "expectation": "cross-origin-resource-sharing-not-implemented",
    "name": "cross-origin-resource-sharing",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CORS",
    "title": "Cross Origin Resource Sharing (CORS)",
    "pass": true,
    "result": "cross-origin-resource-sharing-not-implemented",
    "score_description": "<p>\n      Content is not visible via cross-origin resource sharing (CORS) files or headers.\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": null
   },
   "redirection": {
    "expectation": "redirection-to-https",
    "name": "redirection",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/TLS#http_redirection",
    "title": "Redirection",
    "pass": true,
    "result": "redirection-to-https",
    "score_description": "<p>\n      Initial redirection is to HTTPS on same host, final destination is HTTPS\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "route": [
     "http://www.mozmurray.co.uk/",
     "https://www.mozmurray.co.uk/"
    ],
    "redirects": true,
    "status_code": 200,
    "destination": "https://www.mozmurray.co.uk/"
   },
   "referrer-policy": {
    "expectation": "referrer-policy-private",
    "name": "referrer-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/Referrer_policy",
    "title": "Referrer Policy",
    "pass": true,
    "result": "referrer-policy-private",
    "score_description": "<p>\n        <code>Referrer-Policy</code> header set to <code>no-referrer</code>, <code>same-origin</code>, <code>strict-origin</code> or <code>strict-origin-when-cross-origin</code>.\n        </p>",
    "recommendation": "<p class=\"obs-none\">None<p>",
    "score_modifier": 5,
    "data": "strict-origin-when-cross-origin",
    "http": true,
    "meta": false
   },
   "strict-transport-security": {
    "expectation": "hsts-implemented-max-age-at-least-six-months",
    "name": "strict-transport-security",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/TLS#http_strict_transport_security_implementation",
    "title": "Strict Transport Security (HSTS)",
    "pass": true,
    "result": "hsts-implemented-max-age-at-least-six-months",
    "score_description": "<p>\n        <code>Strict-Transport-Security</code> header set to a minimum of six months (15768000).\n        </p>",
    "recommendation": "<p>\n      Consider preloading: this requires adding the <code>preload</code> and <code>includeSubDomains</code> directives and setting <code>max-age</code> to at least <code>31536000</code> (1 year), and submitting your site to <a href=\"https://hstspreload.org/\" target=\"_blank\" rel=\"noreferrer\" class=\"external\">https://hstspreload.org/</a>.\n      </p>",
    "score_modifier": 0,
    "data": "max-age=31536000",
    "max_age": 31536000,
    "preload": false,
    "preloaded": false,
    "include_sub_domains": false
   },
   "subresource-integrity": {
    "expectation": "sri-implemented-and-external-scripts-loaded-securely",
    "name": "subresource-integrity",
    "link": "/en-US/docs/Web/Security/Subresource_Integrity",
    "title": "Subresource Integrity",
    "pass": false,
    "result": "sri-not-implemented-but-external-scripts-loaded-securely",
    "score_description": "<p>\n      Subresource Integrity (SRI) not implemented, but all external scripts are loaded over HTTPS.\n      </p>",
    "recommendation": "<p>\n      Add SRI to external scripts.\n      </p>",
    "score_modifier": -5,
    "data": {
     "https://fd.cleantalk.org/ct-bot-detector-wrapper.js?ver=6.86": {
      "integrity": null,
      "crossorigin": null
     }
    }
   },
   "x-content-type-options": {
    "expectation": "x-content-type-options-nosniff",
    "name": "x-content-type-options",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/MIME_types",
    "title": "X-Content-Type-Options",
    "pass": true,
    "result": "x-content-type-options-nosniff",
    "score_description": "<p>\n      <code>X-Content-Type-Options</code> header set to <code>nosniff</code>.\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": "nosniff"
   },
   "x-frame-options": {
    "expectation": "x-frame-options-sameorigin-or-deny",
    "name": "x-frame-options",
    "link": "/en-US/docs/Web/Security/Attacks/Clickjacking",
    "title": "X-Frame-Options",
    "pass": true,
    "result": "x-frame-options-sameorigin-or-deny",
    "score_description": "<p>\n      <code>X-Frame-Options</code> (XFO) header set to <code>SAMEORIGIN</code> or <code>DENY</code>.\n      </p>",
    "recommendation": "",
    "score_modifier": 5,
    "data": "SAMEORIGIN"
   },
   "cross-origin-resource-policy": {
    "expectation": "corp-implemented-with-same-site",
    "name": "cross-origin-resource-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CORP",
    "title": "Cross Origin Resource Policy",
    "pass": null,
    "result": "corp-not-implemented",
    "score_description": "<p>\n      Cross Origin Resource Policy (CORP) is not implemented (defaults to <code>cross-origin</code>).\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": null,
    "http": false,
    "meta": false
   }
  }
 }
}