Found
Duration
Date
IP
- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 172.67.73.252 + Target Hostname: saddlebackleather.com + Target Port: 80 + Platform: Linux/Unix + Start Time: 2026-08-31 15:03:45 (GMT-4) --------------------------------------------------------------------------- + Server: cloudflare + Multiple IPs found: 172.67.73.252, 104.26.13.129, 104.26.12.129, 2606:4700:20::681a:c81, 2606:4700:20::ac43:49fc, 2606:4700:20::681a:d81 + [999986] /: Retrieved via header: 1.1 google. + [999100] /: Uncommon header(s) 'x-bc-is-ha' found, with contents: 1. + [999100] /: Uncommon header(s) 'x-request-id' found, with contents: 3a15d51b78c1eba8aac746aefba55cd7. + [999100] /: Uncommon header(s) 'x-bc-store-id' found, with contents: 1000984217. + [999100] /: Uncommon header(s) 'bc-ray' found, with contents: 1,1. + [999100] /: Uncommon header(s) 'x-makeswift-page-locale' found, with contents: en. + [011799] /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc + [999106] /: Cloudflare detected via cf-ray header. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks. See: https://github.com/sullo/nikto/wiki/Using-a-Proxy + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [95] /nikto-test-kmpwt7Kn.html: Cookie SF-CSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-kmpwt7Kn.html: Cookie fornax_anonymousId created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-kmpwt7Kn.html: Cookie XSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [000427] /nikto-test-kmpwt7Kn.html: Link header(s) found with value(s): <https://na.shgcdn3.com/collector.js>; rel=preload; as=script, <https://static.klaviyo.com/onsite/js/R4QqH9/klaviyo.js?company_id=R4QqH9>; rel=preload; as=script, <https://cdn.attn.tv/saddlebackleather/dtag.js>; rel=preload; as=script, <https://bigcommerce-storefront.getredo.com/main.js>; rel=preload; as=script, <https://cdn11.bigcommerce.com/s-uiywfsyvbe>; rel=preconnect; as=font; crossorigin=anonymous, <https://fonts.googleapis.com/>; rel=preconnect; as=font; crossorigin=anonymous, <https://fonts.gstatic.com/>; rel=preconnect; as=font; crossorigin=anonymous, <https://fonts.googleapis.com/css?family=Poppins:400,700&display=swap>; rel=preload; as=style, <https://cdn11.bigcommerce.com/s-uiywfsyvbe/stencil/d610cdf0-84fe-013f-34e5-6a410f8ced82/e/c831ec20-6743-013f-b3f9-36eb2f8535d7/css/theme-134d9f30-8791-013f-f90d-36526ffe589a.css>; rel=preload; as=style, <https://cdn11.bigcommerce.com/s-uiywfsyvbe/stencil/d610cdf0-84fe-013f-34e5-6a410f8ced82/e/c831ec20-6743-013f-b3f9-36eb2f8535d7/css/vault-134d9f30-8791-013f-f90d-36526ffe589a.css>; rel=preload; as=style, <https://cdn11.bigcommerce.com/s-uiywfsyvbe/stencil/d610cdf0-84fe-013f-34e5-6a410f8ced82/e/c831ec20-6743-013f-b3f9-36eb2f8535d7/css/custom-134d9f30-8791-013f-f90d-36526ffe589a.css>; rel=preload; as=style, <https://cdn11.bigcommerce.com/s-uiywfsyvbe/stencil/d610cdf0-84fe-013f-34e5-6a410f8ced82/e/c831ec20-6743-013f-b3f9-36eb2f8535d7/css/corporate-134d9f30-8791-013f-f90d-36526ffe589a.css>; rel=preload; as=style, <https://cdn11.bigcommerce.com/s-uiywfsyvbe/stencil/d610cdf0-84fe-013f-34e5-6a410f8ced82/e/c831ec20-6743-013f-b3f9-36eb2f8535d7/css/ourstory-134d9f30-8791-013f-f90d-36526ffe589a.css>; rel=preload; as=style. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [999100] /dump.jks: Uncommon header(s) 'reporting-endpoints' found, with contents: cf-csp-endpoint="https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=KcBSJRbMrQbvA0FYSgdPmY81XjrOdpaiN3Ygajw_lz0-1788203043.1967556-1.0.1.1-aHBzqYzO6yvJSk5IsTuePEgMDEYVoYuCWryz190RSm4NmDsLN2vg_hhVt5Ip7oiebzfQldEd7cvnA4jO5h46EW1uDzm68RLH1Lzkl7xZTq3D6CSBBTxv0m5e7UCx1yFujCHvLEfvNPuks9me0gXzdYYD2n4ZyYBX7D6SdFOQJyv_v1A7ptz4oQ3ilRnnIn3v". + [800264] /: cloudflare - Cloudflare detected via banner. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks if not already proxying. + Scan terminated: 0 errors and 17 items reported on the remote host + End Time: 2026-08-31 15:04:46 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested