Language Bazaar
Interactive lessons in conversational modern Hebrew that treat speaking like a sport and reading like a puzzle.
Compare
Security headers: A, 90 out of 100
Number 10 of 95 in the ranking. Missing 1 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
Missing 1
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
Sent 8
-
Content-Security-Policy 25 of 25
default-src 'self';script-src 'self' 'nonce-LLSuZJ0tkimki24i4DyNCg==';style-src 'self' 'nonce-LLSuZJ0tkimki24i4DyNCg==' 'sha256-KmuybpeIODTiqckdvTvlqNTvo/FCXZzUUlV4T9gJkoo=' 'sha256-k0WLd3ulXPrpY7QZFCS+T0vX8ftqew4kV7Dl98xSR+o=' https://fonts.googleapis.com;img-src 'self' data: https://*.s3.amazonaws.com https://s3.amazonaws.com https://*.s3.us-east-1.amazonaws.com https://hebrewtoday.s3.us-east-1.amazonaws.com;connect-src 'self' https://*.amazonaws.com https://*.stripe.com;font-src 'self' https://fonts.gstatic.com;object-src 'none';media-src 'self' blob: https://*.s3.amazonaws.com https://*.s3.us-east-1.amazonaws.com https://hebrewtoday.s3.us-east-1.amazonaws.com;frame-src 'self' https://*.stripe.com;script-src-attr 'unsafe-inline';base-uri 'self';form-action 'self';frame-ancestors 'self';upgrade-insecure-requests
-
Strict-Transport-Security 20 of 20
max-age=15552000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
CSP frame-ancestors
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
Cross-Origin-Opener-Policy 5 of 5
same-origin
-
Cross-Origin-Resource-Policy 5 of 5
same-origin
-
No version disclosure 5 of 5