HTTP Observatory Report: lpd.eea.europa.eu Score Rule Description -50 cross-origin-resource-sharing Content is visible via cross-origin resource sharing (CORS) file or headers. -25 content-security-policy Content Security Policy (CSP) header not implemented. -20 strict-transport-security HTTP Strict Transport Security (HSTS) header not implemented. -20 x-frame-options X-Frame-Options (XFO) header not implemented. -10 redirection Redirects to HTTPS eventually, but initial redirection is to another HTTP URL. -5 subresource-integrity Subresource Integrity (SRI) not implemented, but all external scripts are loaded over HTTPS. -5 x-content-type-options X-Content-Type-Options header not implemented. 0 cookies All cookies use the Secure flag and all session cookies use the HttpOnly flag. 0 contribute Contribute.json isn't required on websites that don't belong to Mozilla. 0 x-xss-protection Deprecated X-XSS-Protection header not implemented. 0 referrer-policy Referrer-Policy header not implemented. Score: 0 Grade: F Full Report Url: https://observatory.mozilla.org/analyze.html?host=lpd.eea.europa.eu