Yapıdan
Free Turkish civil engineering learning resources, with technical articles, worked examples, regulatory references and browser-based calculators. Some tools have a timed preview or require free membership. Educational exploration; outputs need independent professional checking.
Compare
Security headers: B, 80 out of 100
Number 32 of 95 in the ranking. Missing 1 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, yapidan.com is more exposed to man-in-the-middle attacks, redirected forms and hijacked payments.
Missing 1
-
Strict-Transport-Security 0 of 20
Tells browsers to use HTTPS for this domain, every time, without trying plain HTTP first.
Without it: The site is open to man-in-the-middle attacks. The first request a user makes (typing the domain, following an old http:// link) can go out unencrypted, and anyone on the same network, such as café, hotel or airport Wi-Fi, can intercept it before the redirect to HTTPS. From there they can read passwords, session cookies and card numbers, serve a fake sign-in page, or inject their own JavaScript into the real one.
Sent 8
-
Content-Security-Policy 25 of 25
default-src 'none'; script-src 'nonce-LEPLPltTeXnOX94WjDcN00' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
same-origin
-
Permissions-Policy 10 of 10
accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
-
Cross-Origin-Opener-Policy 5 of 5
same-origin
-
Cross-Origin-Resource-Policy 5 of 5
same-origin
-
No version disclosure 5 of 5
server: cloudflare