- Technical name
- Transport security, header values, cookies and exposure
- What it checks
- HTTPS after redirects and whether http:// permanently redirects to HTTPS; the TLS certificate (trust, hostname, protocol version, issuer, expiry); security header values — HSTS max-age (at least 180 days) and syntax, CSP directives including 'unsafe-inline', 'unsafe-eval', broad script sources, nonces and hashes, object-src and base-uri, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy, Permissions-Policy; cookie flags (Secure, HttpOnly, SameSite, Domain) by name only; CORS with one harmless test origin; mixed content; security.txt; version-revealing headers and public source maps; technologies and visible surface such as login forms and API references; inline event handlers and scripts without Subresource Integrity, flagged for manual review.
- How it's scored
- Starts at 100. Not HTTPS −40, invalid or expired certificate −40, failed TLS connection −30, CORS trusting any origin with credentials −25, no HSTS −15, no CSP −12, no http→https redirect −10, no clickjacking protection −8, active mixed content −8, Report-Only CSP −8, no X-Content-Type-Options −6, 'unsafe-inline' scripts −6, cookies without Secure −6, weak HSTS −5, and smaller deductions for other weak values. Many informational findings, such as a missing security.txt, cost nothing.
- Tested with
- Python requests (GET and HEAD only) + the standard-library ssl module