A+
Overall grade — 100/100
Security Report

Analysis of

https://webguardian.cloud  ·  HTTP 200  ·  0.18 s

Excellent! Your site follows security best practices. Keep it up.

HTTPS active HTTP to HTTPS redirect 100/100 · A+
Scan another site
Lock in this Grade A+ on webguardian.cloud continuously Flash Offer -50%

An SSL renewal, CI/CD deployment, or server update can silently break your security headers. My Sentinel engine inspects your domain every 6 hours and alerts you before any incident occurs.

// DOMAIN NAME OR WEB URL
Content Security Policy (CSP)
22/22 pts
Critical Configured
Detected value: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src…
Risk if missing

Without CSP, an attacker can inject malicious code into your page (XSS attack). They could steal visitor sessions, display fake forms or redirect them to a fraudulent site — without your knowledge.

Benefit

The browser knows exactly which scripts and resources are allowed on your site. Any injection attempt is automatically blocked, even if a vulnerability exists in your code.

Quick tip
Start with: Content-Security-Policy: default-src 'self' then gradually refine according to your dependencies (CDN, analytics, fonts…).
MDN Documentation →
HTTP Strict Transport Security (HSTS)
20/20 pts
Critical Configured
Detected value: max-age=31536000; includeSubDomains; preload
Risk if missing

Without HSTS, an attacker can intercept your visitors' connection before HTTPS is established (man-in-the-middle attack). Passwords and sensitive data may travel in plain text without anyone noticing.

Benefit

The browser is forced to always use HTTPS for this domain (according to max-age). The connection is encrypted from the very first request, with no possible exception.

Quick tip
Add: Strict-Transport-Security: max-age=31536000; includeSubDomains — and consider HSTS preloading for maximum protection.
MDN Documentation →
Framing protection (X-Frame-Options)
13/13 pts
High Configured
Detected value: SAMEORIGIN
Risk if missing

Your site can be embedded in an invisible frame on another page. An attacker can overlay transparent elements and trick you into clicking unintended actions without your knowledge (clickjacking) — such as confirming a payment or changing a password.

Benefit

Your site cannot be embedded in an external frame. Clickjacking attempts are neutralised before the visitor even interacts.

Quick tip
Add: X-Frame-Options: SAMEORIGIN to allow embedding only from your own domain, or DENY to block it entirely.
MDN Documentation →
Content type enforcement (X-Content-Type-Options)
13/13 pts
High Configured
Detected value: nosniff
Risk if missing

Without this header, the browser may guess a file's type and execute malicious code disguised as an image or text document. A file uploaded by a malicious user could be interpreted as JavaScript.

Benefit

Files are always executed according to their officially declared type. Disguised malicious uploads are neutralised, even if your server-side validation is imperfect.

Quick tip
Simple and effective: X-Content-Type-Options: nosniff — one line, instant protection.
MDN Documentation →
Referrer Policy
10/10 pts
Medium Configured
Detected value: strict-origin-when-cross-origin
Risk if missing

By default, the full URL of your page is sent to third-party sites when a visitor clicks a link. Potentially sensitive data (URL tokens, IDs, search parameters) can leak to external services such as analytics or CDN.

Benefit

You precisely control which information is shared. Your internal URL remains private; only the origin (domain) is transmitted if needed.

Quick tip
Recommended: Referrer-Policy: strict-origin-when-cross-origin — a good balance between privacy and functionality.
MDN Documentation →
Permissions Policy
10/10 pts
Medium Configured
Detected value: geolocation=(), camera=(), microphone=(), payment=(), usb=()
Risk if missing

Without this header, embedded third-party scripts (ads, widgets, trackers) can silently access sensitive features: your visitors' camera, microphone, geolocation or accelerometer — without your explicit authorisation.

Benefit

You define a whitelist of browser APIs allowed on your site. Even a compromised third-party script cannot access these sensitive features.

Quick tip
Minimal example: Permissions-Policy: camera=(), microphone=(), geolocation=() — adapt according to your actual needs.
MDN Documentation →
Tab isolation (COOP)
9/9 pts
Medium Configured
Detected value: same-origin
Risk if missing

A malicious page opened from your site in a new tab can access your page's window object and spy on it (cross-origin leak). This potentially exposes session data or displayed information.

Benefit

Your page is isolated from other browsing contexts. Even if a user opens a malicious link from your site, the two pages cannot communicate.

Quick tip
Add: Cross-Origin-Opener-Policy: same-origin — also required to safely enable SharedArrayBuffer.
MDN Documentation →
External resource restriction (COEP)
3/3 pts
Low Configured
Detected value: require-corp
Risk if missing

Your page can load resources from any external origin without explicit restriction, opening attack vectors related to cross-origin resources.

Benefit

Only resources whose server explicitly allows embedding can be loaded on your page. Strengthens isolation and protects against side-channels like Spectre.

Quick tip
Add: Cross-Origin-Embedder-Policy: require-corp — note: this requires all your third-party resources to support CORS or CORP.
MDN Documentation →
Independent SecOps Defense & Support

Ready to automate compliance and defense for webguardian.cloud ?

Founder and managing director of Mx Solutions in Luxembourg, I built WebGuardian to deliver autonomous continuous monitoring, regulatory reporting compliance (NIS2, GDPR), and real-time alerts upon any security regression.

7% FR sites with no CSP · 1/4 vulnerable cookies · 72h detection time · 0% obsolete TLS · 4% HSTS missing · 5% clickjacking risk · 7% FR sites with no CSP · 1/4 vulnerable cookies · 72h detection time · 0% obsolete TLS · 4% HSTS missing · 5% clickjacking risk ·
1993
SITES SCANNED
since launch
<0.24s
SCAN TIME
complete result
24/7
MONITORING
continuous surveillance
4227
THREATS DETECTED
in real time
Web Standards & Best Practices
OWASP Guidelines W3C & IETF Standards TLS / HTTPS Encryption MDN Web Security Non-Intrusive Diagnostic

Three steps. Zero friction.

From first scan to continuous monitoring, everything is automated from a single dashboard.

01 —

Scan your site

Enter your URL. WebGuardian analyses your HTTP headers, TLS configuration and attack surface in seconds.

02 —

Get your score

A readable, prioritised report. Each point is explained with its concrete risks and expected benefits — no jargon.

03 —

Stay monitored continuously

Enable automatic monitoring. Instant alerts whenever a new risk is detected on your site.

Everything your security needs.

A complete platform built for modern teams — no security expertise required.

Instant diagnostic

Full analysis of the main attack vectors from the very first URL submitted.

24/7 monitoring

Permanent surveillance with proactive detection of security regressions.

Critical alerts

Slack, email or webhook notifications whenever a score degradation is detected.

Unified dashboard

All your sites, scores and history in a clear interface, mobile and desktop.

PDF reports

Export your diagnostic reports as PDFs for your teams or clients.

API & Integrations

Connect WebGuardian to your CI/CD, SIEM or DevSecOps tools.

Do you really know your exposed surface?

Launch your first scan in 30 seconds. No credit card, no installation.

Test for free now

100% free · No sign-up · Result in < 30 seconds