Content Security Policy (CSP)
22/22 pts
Critical
Configured
Detected value:
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src…
Without CSP, an attacker can inject malicious code into your page (XSS attack). They could steal visitor sessions, display fake forms or redirect them to a fraudulent site — without your knowledge.
The browser knows exactly which scripts and resources are allowed on your site. Any injection attempt is automatically blocked, even if a vulnerability exists in your code.
Start with: Content-Security-Policy: default-src 'self' then gradually refine according to your dependencies (CDN, analytics, fonts…).
MDN Documentation →
HTTP Strict Transport Security (HSTS)
20/20 pts
Critical
Configured
Detected value:
max-age=31536000; includeSubDomains; preload
Without HSTS, an attacker can intercept your visitors' connection before HTTPS is established (man-in-the-middle attack). Passwords and sensitive data may travel in plain text without anyone noticing.
The browser is forced to always use HTTPS for this domain (according to max-age). The connection is encrypted from the very first request, with no possible exception.
Add: Strict-Transport-Security: max-age=31536000; includeSubDomains — and consider HSTS preloading for maximum protection.
MDN Documentation →
Framing protection (X-Frame-Options)
13/13 pts
High
Configured
Detected value:
SAMEORIGIN
Your site can be embedded in an invisible frame on another page. An attacker can overlay transparent elements and trick you into clicking unintended actions without your knowledge (clickjacking) — such as confirming a payment or changing a password.
Your site cannot be embedded in an external frame. Clickjacking attempts are neutralised before the visitor even interacts.
Add: X-Frame-Options: SAMEORIGIN to allow embedding only from your own domain, or DENY to block it entirely.
MDN Documentation →
Content type enforcement (X-Content-Type-Options)
13/13 pts
High
Configured
Detected value:
nosniff
Without this header, the browser may guess a file's type and execute malicious code disguised as an image or text document. A file uploaded by a malicious user could be interpreted as JavaScript.
Files are always executed according to their officially declared type. Disguised malicious uploads are neutralised, even if your server-side validation is imperfect.
Simple and effective: X-Content-Type-Options: nosniff — one line, instant protection.
MDN Documentation →
Referrer Policy
10/10 pts
Medium
Configured
Detected value:
strict-origin-when-cross-origin
By default, the full URL of your page is sent to third-party sites when a visitor clicks a link. Potentially sensitive data (URL tokens, IDs, search parameters) can leak to external services such as analytics or CDN.
You precisely control which information is shared. Your internal URL remains private; only the origin (domain) is transmitted if needed.
Recommended: Referrer-Policy: strict-origin-when-cross-origin — a good balance between privacy and functionality.
MDN Documentation →
Permissions Policy
10/10 pts
Medium
Configured
Detected value:
geolocation=(), camera=(), microphone=(), payment=(), usb=()
Without this header, embedded third-party scripts (ads, widgets, trackers) can silently access sensitive features: your visitors' camera, microphone, geolocation or accelerometer — without your explicit authorisation.
You define a whitelist of browser APIs allowed on your site. Even a compromised third-party script cannot access these sensitive features.
Minimal example: Permissions-Policy: camera=(), microphone=(), geolocation=() — adapt according to your actual needs.
MDN Documentation →
Tab isolation (COOP)
9/9 pts
Medium
Configured
Detected value:
same-origin
A malicious page opened from your site in a new tab can access your page's window object and spy on it (cross-origin leak). This potentially exposes session data or displayed information.
Your page is isolated from other browsing contexts. Even if a user opens a malicious link from your site, the two pages cannot communicate.
Add: Cross-Origin-Opener-Policy: same-origin — also required to safely enable SharedArrayBuffer.
MDN Documentation →
External resource restriction (COEP)
3/3 pts
Low
Configured
Detected value:
require-corp
Your page can load resources from any external origin without explicit restriction, opening attack vectors related to cross-origin resources.
Only resources whose server explicitly allows embedding can be loaded on your page. Strengthens isolation and protects against side-channels like Spectre.
Add: Cross-Origin-Embedder-Policy: require-corp — note: this requires all your third-party resources to support CORS or CORP.
MDN Documentation →