Summary
A Concise Overview of the scan result of url https://www.xms-portal.com/xms/onlineReference/create?tkn=d40daf046edf4d43a1f8f7e2d7d2d60d&refId=&reference=screening&tokenId=d893d4d2-1621-463e-b8e0-e701f9ba3451&isTokenValid=true&_xmscs=d0f304a6665d40dc5ee4a1b0c2386f7ee0cb075f49aa330802b44d5b1a1e3eaa5aea09629b5a6c0b
- Document
- HTML
- 1
- StyleSheets
- 6
- Scripts
- 14
- Font
- 0
- Images
- 5
- Links
- 0
- JavaScript Variables
- 479
- Console log messages
- 0
- Network
- Requests
- 34
- Bytes Transferred
- 5.85MB
- Bytes Total
- 6.33MB
- DNS Record
- A Record
- 1
- Technology
- JavaScript frameworks
- 1
- JavaScript libraries
- 1
- Security
- 1
- Analytics
- 1
Document
Links
The outgoing links identified from the page.
| Link | Text |
|---|
JavaScript Variables
Global JavaScript variables are variables that are defined outside of any function or block scope in JavaScript.
Technology
The technologies identified are present on the scanned URL.
| Name | Description | Detected patterns |
|---|---|---|
| Analytics | ||
Google Analytics | Google Analytics is a free web analytics service that tracks and reports website traffic. | Type: scriptSrc Regex: googletagmanager\.com\/gtag\/js |
| JavaScript frameworks | ||
AngularJS | AngularJS is a JavaScript-based open-source web application framework led by the Angular Team at Google. | Type: scriptSrc Regex: (?!angular\.io)\bangular.{0,32}\.js |
| Security | ||
| HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS. | Type: headers Name: strict-transport-security Regex: (?:) | |
| JavaScript libraries | ||
jQuery | jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax. | Type: scriptSrc Regex: jquery |
Performance
The speed and efficiency of the scanned URL loads and displays its content.
- dns
- 1 msGood
- tcp
- 1 msGood
- requestTime
- 401 msNeeds Improvement
- dom
- 2508 msPoor
DNS Record
A DNS record maps a domain name to an IP address or other resource information.
| Type | Name | Content | DNSSEC |
|---|---|---|---|
| A | www.xms-portal.com | 195.138.205.137 | no |
SSL Certificate
An SSL certificate is a digital certificate that verifies the authenticity and encrypts the communication between a website and its visitors.
| Subject | Issue date | Expiry date | Valid |
|---|---|---|---|
www.xms-portal.com | 8/18/2026 | 8/19/2027 | 1 year 1 day |
www.googletagmanager.com | 8/18/2026 | 8/19/2027 | 1 year 1 day |
www.google-analytics.com | 8/18/2026 | 8/19/2027 | 1 year 1 day |
js-agent.newrelic.com | 8/18/2026 | 8/19/2027 | 1 year 1 day |
HTTP Headers
HTTP Header
An HTTP header is a component of an HTTP request or response that contains additional information about the message being sent or received.
| Name | Value |
|---|---|
| Cache-Control | no-store |
| Connection | keep-alive |
| Content-Language | en-US |
| Content-Security-Policy | script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://*.reed.co.uk https://platform.linkedin.com https://platform.kortical.com https://www.linkedin.com https://whatfix.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://*.google-analytics.com https://region1.google-analytics.com https://tagmanager.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam.eu01.nr-data.net;style-src 'self' data: 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com; img-src 'self' data: https://www.googletagmanager.com https://resources.reed.com https://uploads-ssl.webflow.com https://*.gstatic.com https://www.google-analytics.com;font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://region1.google-analytics.com https://platform.kortical.com https://www.google-analytics.com https://bam.nr-data.net https://bam.eu01.nr-data.net; object-src 'none' |
| Content-Type | text/html;charset=UTF-8 |
| Date | Wed, 19 Aug 2026 10:04:44 GMT |
| Keep-Alive | timeout=60 |
| Permissions-Policy | geolocation=(self "https://*.xms-portal.com" "https://*.reedglobal.com" "https://*.reed.co.uk" "https://*.linkedin.com") |
| Referrer-Policy | strict-origin-when-cross-origin |
| Server | SomeWebServer |
| Strict-Transport-Security | max-age=31536000; includeSubDomains |
| Transfer-Encoding | chunked |
| Vary | origin,access-control-request-method,access-control-request-headers,accept-encoding |
| X-Content-Type-Options | nosniff |
| X-Frame-Options | SAMEORIGIN |
Content Security Policy
Content Security Policy (CSP) is a security mechanism that helps prevent cross-site scripting (XSS) and other code injection attacks by specifying which content sources are allowed to be loaded on a web page.
| Name | Value |
|---|
Cookies
Cookies are small pieces of data stored on a user's web browser to track and remember information about their browsing activity on a website.
| Name | Value | Domain/Path | Expires | Secure | HTTP Only |
|---|---|---|---|---|---|
| JSESSIONID | [JSESSIONID redacted] | www.xms-portal.com/xms | 12/31/1969, 11:59:59 PM | yes | yes |
| XSRF-TOKEN | [XSRF-TOKEN redacted] | www.xms-portal.com/ | 12/31/1969, 11:59:59 PM | no | no |
| NSC_WT_xxx.ynt-qpsubm.dpn_ENA_TTM | ffffffffc3a0e76c45525d5f4f58455e445a4a42b6db | www.xms-portal.com/ | 8/20/2026, 10:05:16 AM | yes | yes |
| _ga_4D384JHZQR | GS2.1.s1787133887$o1$g0$t1787133887$j60$l0$h0 | .xms-portal.com/ | 9/23/2027, 10:04:47 AM | no | no |
| _ga | GA1.2.585180427.1787133888 | .xms-portal.com/ | 9/23/2027, 10:04:47 AM | no | no |
| _gid | GA1.2.246082633.1787133888 | .xms-portal.com/ | 8/20/2026, 10:04:47 AM | no | no |
| _gat_gtag_UA_126912110_1 | 1 | .xms-portal.com/ | 8/19/2026, 10:05:47 AM | no | no |