E
47/100

Security posture: At risk. Passive scan · 20 checks · HTTP/1.1 · HTTP 200.

Speed test →
Critical
1
fix immediately
High
0
serious risk
Medium
1
should address
Low / Info
2
hardening

Findings (worst first · 1 passed)

  • Critical Publicly accessible: https://www.daraz.com.bd/.env · Exposure
    Exposed environment file — often holds DB passwords, API keys and secrets (HTTP 200).
    Fix: Block access to this path at the web server, or remove the file.
  • ! Medium Missing Content-Security-Policy header · Headers
    Whitelists resource origins — the strongest defence against XSS.
    Fix: Add the Content-Security-Policy response header.
  • Low Missing Referrer-Policy header · Headers
    Controls how much referrer URL is leaked to other sites.
    Fix: Add the Referrer-Policy response header.
  • Low Missing Permissions-Policy header · Headers
    Restricts access to camera, mic, geolocation, etc..
    Fix: Add the Permissions-Policy response header.
  • Pass Served over HTTPS · Transport
    The connection is TLS-encrypted.

Security Headers

Present Strict-Transport-Security Forces browsers to use HTTPS (HSTS) — blocks SSL-strip attacks
Missing Content-Security-Policy Whitelists resource origins — the strongest defence against XSS
Present X-Content-Type-Options Stops MIME-type sniffing (nosniff)
Present X-Frame-Options Blocks the site being framed — anti-clickjacking
Missing Referrer-Policy Controls how much referrer URL is leaked to other sites
Missing Permissions-Policy Restricts access to camera, mic, geolocation, etc.

TLS Certificate

Tls12 Negotiated protocol
Issuer GlobalSign GCC R3 OV TLS CA 2024
265d Valid 2026-03-10 → 2027-04-11
Yes HTTP redirects to HTTPS
On HSTS (Strict-Transport-Security)

Cookies

NoneThe homepage set no cookies on this request.

Sensitive File Exposure

200 https://www.daraz.com.bd/.git/config
Exposed https://www.daraz.com.bd/.env ↗ Exposed environment file — often holds DB passwords, API keys and secrets
200 https://www.daraz.com.bd/.svn/entries
200 https://www.daraz.com.bd/config.php.bak
200 https://www.daraz.com.bd/wp-config.php.bak
200 https://www.daraz.com.bd/.htaccess
200 https://www.daraz.com.bd/phpinfo.php
301 https://www.daraz.com.bd/server-status
200 https://www.daraz.com.bd/.DS_Store
200 https://www.daraz.com.bd/backup.zip

Only well-known, low-risk paths are checked — no directory brute-forcing.

How this works: StatVoid ran a passive scan of daraz.com.bd — only ordinary GET requests to public URLs, reading the headers, cookies, TLS certificate and a short list of well-known sensitive paths the server exposes. Nothing was attacked, injected or brute-forced. Grades are a guide, not a certification. Want performance too? Run the page speed test for daraz.com.bd.