Security Checks

Educational, actionable checks backed by scan data.

Verify HTTP Strict Transport Security (HSTS) is enabled.
Check Content Security Policy (CSP) coverage and common pitfalls.
Validate a baseline set of modern security headers.
Confirm HTTP requests redirect to HTTPS consistently.
Detect HTTP subresources loaded on an HTTPS page.
Check cookies for Secure, HttpOnly, and SameSite flags.
Verify X-Frame-Options / frame-ancestors configuration.
Verify X-Content-Type-Options: nosniff is set.
Ensure referrer information is not over-shared.
Audit browser feature permissions (camera, microphone, etc.).