Some insecurity improvements could be made:
Retirable jQuery code detected: http://retire.insecurity.today/#!/scan/4122b16928ea35e40fb718fafe30e12d2e0f9a6caad3fd435b903f7f5176b512
SRI-hashed not set because not generated, creates “same origin” threats → F-status:
https://sritest.io/#report/41b932e8-e0d6-4021-b4cb-c3891a6b697f
Cert. Strict Transport Security (HSTS): UNKNOWN
F-D-X-status: https://observatory.mozilla.org/analyze.html?host=www.ibmirror.com
See recommended change also.
polonus (volunteer website security analyst and website error-hunter)