Security Analysis Results

web.whatsapp.com

Comprehensive domain security and infrastructure analysis

Live Website Preview

website screenshot of https://web.whatsapp.com/

No Security Risks Detected

This domain appears to be safe and secure

100%
Score

Disclaimer: This assessment is based on automated analysis of publicly available information. Results are for informational purposes only. For critical applications, consult security professionals.

Scan Information

Last checked:July 17, 2025 11:48:54
Scan Complete

Refresh page after 10 minutes
for updated results

Page Information

Target URL
https://web.whatsapp.com/
Page Title
WhatsApp Web
web.whatsapp.com faviconSite Favicon
Status
Active

Host Information

Domain
web.whatsapp.com
Server
N/A
Country
United States
IP Address
31.13.66.56
ASN Information
32934
FACEBOOK

Technologies

HSTS logo
HSTS
Security
HTTP/3 logo
HTTP/3
Miscellaneous

SSL Certificate

HTTPS Enabled
Secure
Certificate Issuer
49m395 Gateway Proxy BISO MITM CA
Valid From
2025-07-12 06:44:12
Valid Until
2025-08-11 06:44:42
Subject Name
web.whatsapp.com

Performance Statistics

13
Total Requests
2
Domains
1
IP Addresses
57.96 KB
Transfer Size
Content Size221.16 KB

HTTP Headers

accept-ch
viewport-width,dpr,Sec-CH-Prefers-Color-Scheme,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Model
accept-ch-lifetime
4838400
alt-svc
h3=":443"; ma=86400
cache-control
private, no-cache, no-store, must-revalidate
cf-team
28b9d08d6c0001003e379cf400000001
content-encoding
zstd
content-security-policy
default-src 'self' blob: 'wasm-unsafe-eval';script-src blob: 'self' 'nonce-ptzB6Clc' 'report-sample' https://static.whatsapp.net https://*.youtube.com https://maps.googleapis.com https://maps.gstatic.com https://lens.google.com/upload 'wasm-unsafe-eval';style-src data: blob: 'self' 'unsafe-inline' https://static.whatsapp.net https://fonts.googleapis.com;connect-src 'self' https://*.whatsapp.net https://www.facebook.com blob: https://crashlogs.whatsapp.net/wa_clb_data https://crashlogs.whatsapp.net/wa_fls_upload_check wss://*.web.whatsapp.com wss://web.whatsapp.com wss://web-fallback.whatsapp.com https://acs.whatsapp.com https://www.whatsapp.com https://dyn.web.whatsapp.com https://graph.whatsapp.com/graphql/ https://graph.facebook.com/graphql ws://web.whatsapp.com wss://web.whatsapp.com:5222 data: https://*.tenor.co https://*.giphy.com https://maps.googleapis.com https://lens.google.com/upload https://*.google.com https://meta-ohttp-relay-prod.fastly-edge.com;font-src data: 'self' https://static.whatsapp.net https://fonts.gstatic.com;img-src 'self' data: blob: https://*.whatsapp.net https://*.fbcdn.net *.tenor.co *.tenor.com *.giphy.com https://*.ytimg.com *.youtube.com https://maps.googleapis.com/maps/api/staticmap;media-src 'self' https://*.whatsapp.net https://*.cdninstagram.com https://*.fbcdn.net blob: mediastream: data: *.tenor.co *.tenor.com https://*.giphy.com;child-src 'self' blob: data:;frame-src 'self' blob: data: https://*.youtube.com;manifest-src 'self' blob: data:;object-src 'self' blob: data: https://lens.google.com/upload;worker-src *.whatsapp.com/static_resources/webworker_v1/init_script/ *.whatsapp.com/sw.js *.whatsapp.com/static_resources/webworker/pdf-worker/ *.whatsapp.com/static_resources/webworker/init_script/;block-all-mixed-content;upgrade-insecure-requests; frame-ancestors https://*.whatsapp.com https://whatsapp.com;
content-type
text/html; charset="utf-8"
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-resource-policy
cross-origin
date
Thu, 17 Jul 2025 11:49:06 GMT
document-policy
force-load-at-top include-js-call-stacks-in-crash-reports
expires
Sat, 01 Jan 2000 00:00:00 GMT
origin-agent-cluster
?1
permissions-policy
accelerometer=(), attribution-reporting=(), autoplay=*, bluetooth=(), camera=(self), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(self), compute-pressure=(), display-capture=(), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(), payment=(), picture-in-picture=*, private-state-token-issuance=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy"
pragma
no-cache
report-to
{"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":259200,"endpoints":[{"url":"https:\/\/web.whatsapp.com\/ajax\/whatsapp_error_reports\/?device_level=unknown&brsid=7528016582271704360&comet_app_key=17&cpp=C3&cv=1024849293&st=1752752946405"}]}, {"max_age":21600,"endpoints":[{"url":"https:\/\/www.whatsapp.com\/whatsapp_browser_error_reports\/"}],"group":"permissions_policy"}
reporting-endpoints
coop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", default="https://web.whatsapp.com/ajax/whatsapp_error_reports/?device_level=unknown&brsid=7528016582271704360&comet_app_key=17&cpp=C3&cv=1024849293&st=1752752946405", permissions_policy="https://www.whatsapp.com/whatsapp_browser_error_reports/"
server-timing
cfReqDur;dur=2377.817
strict-transport-security
max-age=63072000; includeSubDomains; preload
vary
Accept-Encoding, User-Agent, Accept-Language Accept-Encoding
x-content-type-options
nosniff
x-fb-connection-quality
EXCELLENT; q=0.9, rtt=1, rtx=1, c=18, mss=1348, tbw=4600, tp=-1, tpl=-1, uplat=112, ullat=0
x-fb-debug
Tf48zbaR/1tjKgcGUEVv7QkutCA6JG9IpwzibkeLIueQrJQ8+tcu6LFFJRl2cRqhhQDpamtyqBzdKmMdZ1r3gw==
x-xss-protection
0
25 headers detected

Technology Stack Analysis

HSTS

HSTS

Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

HTTP/3

HTTP/3

Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

Website Cookies 1

wa_ul

.web.whatsapp.com

HttpOnly Secure Lax
Value
71e58caf-49bc-44cb-b2c3-7e6944419f8e
Expires:10/15/2025

External Links 0

Requested Domains 2

static.whatsapp.net

Unknown Type
No category information available

web.whatsapp.com

Subdomain
No category information available
LinkCheck

© 2025 LinkCheck. Secure domain analysis you can trust.