30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.10.01 | Validate presence of Strict-Transport-Security (HSTS) header with max-age >= 31536000 | HSTS present with adequate max-age |
| 7.10.02 | Validate presence of Content-Security-Policy (CSP) header | CSP header present |
| 7.10.03 | Validate X-Frame-Options header is set to DENY or SAMEORIGIN | Clickjacking protection enabled |
| 7.10.04 | Validate X-Content-Type-Options is set to nosniff | MIME sniffing prevented |
| 7.10.05 | Validate Referrer-Policy is set to strict-origin-when-cross-origin or stricter | Referrer leakage controlled |
| 7.10.06 | Validate Permissions-Policy header restricts unnecessary browser features (camera, microphone, geolocation) | Feature restrictions present |
| 7.10.07 | Validate X-XSS-Protection header is absent or set to 0 (deprecated, can cause issues) | Not relying on deprecated protection |
| 7.10.08 | Validate Cross-Origin-Opener-Policy (COOP) and Cross-Origin-Embedder-Policy (COEP) headers present | Cross-origin isolation configured |
| 7.10.09 | Validate no server version information leaked in response headers (Server, X-Powered-By) | Server info suppressed |
| 7.10.10 | Compute Security Headers Completeness composite score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.10.11 | Validate CSP does not use unsafe-inline for script-src | No unsafe-inline |
| 7.10.12 | Validate CSP does not use unsafe-eval for script-src | No unsafe-eval |
| 7.10.13 | Validate CSP does not use wildcard (*) sources | No wildcard sources |
| 7.10.14 | Validate CSP includes report-uri or report-to directive for violation monitoring | CSP reporting configured |
| 7.10.15 | Validate CSP frame-ancestors directive restricts embedding | Embedding restricted |
| ID | Check | Passes when |
|---|---|---|
| 7.10.16 | Validate all cookies set with Secure flag | Secure flag on all cookies |
| 7.10.17 | Validate session cookies set with HttpOnly flag | HttpOnly on session cookies |
| 7.10.18 | Validate cookies set with appropriate SameSite attribute (Strict or Lax) | SameSite configured |
| 7.10.19 | Validate cookie expiration is appropriate (no indefinite session cookies) | Reasonable expiration |
| 7.10.20 | Validate no sensitive data stored in cookies (tokens should be opaque) | No sensitive data in cookie values |
| ID | Check | Passes when |
|---|---|---|
| 7.10.21 | Validate TLS version is 1.2 or higher (no TLS 1.0/1.1) | TLS >= 1.2 |
| 7.10.22 | Validate certificate chain is complete and valid | Valid certificate chain |
| 7.10.23 | Validate cipher suite strength (no weak ciphers like RC4, DES, 3DES) | Strong ciphers only |
| ID | Check | Passes when |
|---|---|---|
| 7.10.24 | Validate externally loaded scripts have Subresource Integrity (SRI) hashes | SRI present on external scripts |
| 7.10.25 | Validate externally loaded stylesheets have SRI hashes | SRI present on external stylesheets |
| 7.10.26 | Detect public-facing JavaScript libraries with known CVE vulnerabilities | No known-vulnerable libraries |
| 7.10.27 | Validate number of third-party scripts is reasonable (not > 30) | Third-party script count controlled |
| ID | Check | Passes when |
|---|---|---|
| 7.10.28 | Detect API endpoints unintentionally exposed to the public (common with Next.js, Express, Laravel) | No unintended public API endpoints |
| 7.10.29 | Validate exposed API endpoints require authentication or rate limiting | Auth or rate limiting present |
| 7.10.30 | Compute Advanced Security Trust Signals composite score | Finalized |
← 7.9 URL Parameter Sanitization7.11 Secret Leak Detection →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).