Overall security score
See the signal. Understand the fix.
Explore how Qourby turns public scan evidence into a prioritized, plain-English security review.
Scanned asset
demo.qourby.com
https://demo.qourby.comReview items
5Prioritized by severityChecks passed
2Visible baseline controlsCoverage
7Outside-in checksThe demo target exposes several medium-priority public hardening gaps across browser and cross-origin controls. The highest-value next step is to review the missing browser security policies before expanding monitoring.
Priority findings
What deserves attention first.
Content-Security-Policy header
The site does not appear to publish a Content-Security-Policy header. This header can reduce the impact of some script injection and content loading mistakes.
Observed evidence
content-security-policy: —X-Frame-Options header
The public response does not appear to publish a frame-embedding policy. Confirm that pages cannot be embedded by untrusted sites in a misleading context.
Observed evidence
server: framework-hintCross-origin resource sharing policy
A public response appears to allow broad cross-origin access. Confirm that sensitive data is limited to trusted origins and is never exposed with credentials.
Observed evidence
server: framework-hintStrict-Transport-Security header
The public response does not include an HSTS policy. HSTS tells browsers to keep using HTTPS after the first successful secure visit.
Observed evidence
strict-transport-security: —Technology hints
Some framework or server hints may be exposed in public responses. Reducing unnecessary version details can limit easy fingerprinting.
Observed evidence
server: framework-hintWhat the full report includes
Ready for technical and non-technical review.
Use the same evidence in a developer handoff, internal security review, or client conversation without translating raw scanner output by hand.
Take the report with you
Unlock the sample export experience, or run a live scan for a domain-specific report.
Ready to check your own public baseline?