RABIT: Jurnal Teknologi dan Sistem Informasi Univrab
Vol 11 No 2 (2026): Juli

EVALUASI HOLISTIK KEAMANAN HTTPS PLATFORM E-COMMERCE INDONESIA : INTEGRASI ANALISIS TLS, HTTP SECURITY HEADERS, DAN VULNERABILITY SCANNING

Farhani Ayu Amalina (Budi Luhur Univeristy)
Ruth Hanseliani (Budi Luhur Univeristy)
Imelda Imelda (Budi Luhur Univeristy)



Article Info

Publish Date
10 Jul 2026

Abstract

The growth of Indonesian e-commerce transactions, which has exceeded 1,200 trillion rupiah, has made online shopping platforms a primary target of cyberattacks, while recurring national data breaches indicate that the presence of HTTPS does not automatically guarantee an adequate level of security. This condition creates a false sense of security, as weak configuration practices—such as vulnerable cipher suites, support for outdated TLS versions, and the absence of HTTP security headers—still open opportunities for attacks. Previous studies have been partial in nature, evaluating only one aspect—TLS/SSL, security headers, or web application vulnerabilities—so no study has assessed all three layers simultaneously in the context of Indonesian e-commerce. Consequently, partial evaluations fail to depict the overall security posture and conceal critical gaps between layers. The novelty of this research lies in its holistic evaluation through the integrated analysis of results from three tools that assess TLS/SSL, HTTP security headers, and vulnerability scanning in a unified manner. This research employs a descriptive-quantitative method with a black-box testing approach through five stages on three Indonesian e-commerce platforms (XX, YY, ZZ) using SSL Labs, Mozilla HTTP Observatory, and OWASP ZAP. The results show that the level of HTTPS security across the three Indonesian e-commerce platforms still varies. Website YY has the best security implementation, with TLS support and security header deployment, although it has application-layer vulnerabilities. Website ZZ has a strong HTTPS implementation but is weak in security headers, while Website XX has the lowest security level as it still supports outdated protocols and has yet to implement several essential security mechanisms. These findings demonstrate that good HTTPS quality does not necessarily guarantee overall system security, making holistic security evaluation highly necessary.

Copyrights © 2026






Journal Info

Abbrev

rabit

Publisher

Subject

Computer Science & IT Engineering

Description

This journal is called RABIT, where the name comes from two words namely, RAB which means Abdurrab University and IT which means information technology, it can be interpreted as a journal of this journal Journal of Informatics Engineering Study Program Pekanbaru Abdurrab University. This RABIT ...