medium
Content-Security-Policy header
Affected: HTTP response headers
The site does not appear to publish a Content-Security-Policy header. This header can reduce the impact of some script injection and content loading mistakes.
Sample report
The demo target has a reasonable public baseline with a few header hardening opportunities.
Overall score
74/100
Generated
June 12, 2026
Scope
Public, non-invasive outside-in checks
Seeded demo data for report review.
Affected: HTTP response headers
The site does not appear to publish a Content-Security-Policy header. This header can reduce the impact of some script injection and content loading mistakes.
Affected: HTTPS configuration
The public response does not include an HSTS policy. HSTS tells browsers to keep using HTTPS after the first successful secure visit.
Affected: Public headers and HTML
Some framework or server hints may be exposed in public responses. Reducing unnecessary version details can limit easy fingerprinting.