E
47/100
daraz.com.bd
https://www.daraz.com.bd/ ↗Security posture: At risk. Passive scan · 20 checks · HTTP/1.1 · HTTP 200.
Critical
1
High
0
Medium
1
Low / Info
2
Findings (worst first · 1 passed)
-
✕
Critical
Publicly accessible: https://www.daraz.com.bd/.env
· Exposure
Exposed environment file — often holds DB passwords, API keys and secrets (HTTP 200).
Fix: Block access to this path at the web server, or remove the file. -
!
Medium
Missing Content-Security-Policy header
· Headers
Whitelists resource origins — the strongest defence against XSS.
Fix: Add the Content-Security-Policy response header. -
•
Low
Missing Referrer-Policy header
· Headers
Controls how much referrer URL is leaked to other sites.
Fix: Add the Referrer-Policy response header. -
•
Low
Missing Permissions-Policy header
· Headers
Restricts access to camera, mic, geolocation, etc..
Fix: Add the Permissions-Policy response header. -
✓
Pass
Served over HTTPS
· Transport
The connection is TLS-encrypted.
Security Headers
Present
Strict-Transport-Security
Forces browsers to use HTTPS (HSTS) — blocks SSL-strip attacks
Missing
Content-Security-Policy
Whitelists resource origins — the strongest defence against XSS
Present
X-Content-Type-Options
Stops MIME-type sniffing (nosniff)
Present
X-Frame-Options
Blocks the site being framed — anti-clickjacking
Missing
Referrer-Policy
Controls how much referrer URL is leaked to other sites
Missing
Permissions-Policy
Restricts access to camera, mic, geolocation, etc.
TLS Certificate
Tls12
Negotiated protocol
Issuer
GlobalSign GCC R3 OV TLS CA 2024
265d
Valid 2026-03-10 → 2027-04-11
Yes
HTTP redirects to HTTPS
On
HSTS (Strict-Transport-Security)
Cookies
NoneThe homepage set no cookies on this request.
Sensitive File Exposure
200
https://www.daraz.com.bd/.git/config
Exposed
https://www.daraz.com.bd/.env ↗
Exposed environment file — often holds DB passwords, API keys and secrets
200
https://www.daraz.com.bd/.svn/entries
200
https://www.daraz.com.bd/config.php.bak
200
https://www.daraz.com.bd/wp-config.php.bak
200
https://www.daraz.com.bd/.htaccess
200
https://www.daraz.com.bd/phpinfo.php
301
https://www.daraz.com.bd/server-status
200
https://www.daraz.com.bd/.DS_Store
200
https://www.daraz.com.bd/backup.zip
Only well-known, low-risk paths are checked — no directory brute-forcing.
How this works: StatVoid ran a passive scan of daraz.com.bd —
only ordinary GET requests to public URLs, reading the headers, cookies, TLS certificate and a short list of
well-known sensitive paths the server exposes. Nothing was attacked, injected or brute-forced. Grades are a
guide, not a certification. Want performance too? Run the
page speed test for daraz.com.bd.