Home / Check catalog / 7. Security & Privacy / 7.10 Advanced Security Trust Signals

7.10 Advanced Security Trust Signals

30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.

Security Headers Completeness

IDCheckPasses whenWeightRuns
7.10.01Validate presence of Strict-Transport-Security (HSTS) header with max-age >= 31536000HSTS present with adequate max-ageCriticalDeterministic
7.10.02Validate presence of Content-Security-Policy (CSP) headerCSP header presentCriticalDeterministic
7.10.03Validate X-Frame-Options header is set to DENY or SAMEORIGINClickjacking protection enabledHeavyDeterministic
7.10.04Validate X-Content-Type-Options is set to nosniffMIME sniffing preventedHeavyDeterministic
7.10.05Validate Referrer-Policy is set to strict-origin-when-cross-origin or stricterReferrer leakage controlledHeavyDeterministic
7.10.06Validate Permissions-Policy header restricts unnecessary browser features (camera, microphone, geolocation)Feature restrictions presentHeavyDeterministic
7.10.07Validate X-XSS-Protection header is absent or set to 0 (deprecated, can cause issues)Not relying on deprecated protectionMediumDeterministic
7.10.08Validate Cross-Origin-Opener-Policy (COOP) and Cross-Origin-Embedder-Policy (COEP) headers presentCross-origin isolation configuredMediumDeterministic
7.10.09Validate no server version information leaked in response headers (Server, X-Powered-By)Server info suppressedMediumDeterministic
7.10.10Compute Security Headers Completeness composite scoreFinalizedCriticalDeterministic

CSP Policy Strictness

IDCheckPasses whenWeightRuns
7.10.11Validate CSP does not use unsafe-inline for script-srcNo unsafe-inlineCriticalDeterministic
7.10.12Validate CSP does not use unsafe-eval for script-srcNo unsafe-evalCriticalDeterministic
7.10.13Validate CSP does not use wildcard (*) sourcesNo wildcard sourcesHeavyDeterministic
7.10.14Validate CSP includes report-uri or report-to directive for violation monitoringCSP reporting configuredHeavyDeterministic
7.10.15Validate CSP frame-ancestors directive restricts embeddingEmbedding restrictedMediumDeterministic

Cookie Security Audit

IDCheckPasses whenWeightRuns
7.10.16Validate all cookies set with Secure flagSecure flag on all cookiesCriticalDeterministic
7.10.17Validate session cookies set with HttpOnly flagHttpOnly on session cookiesHeavyDeterministic
7.10.18Validate cookies set with appropriate SameSite attribute (Strict or Lax)SameSite configuredHeavyDeterministic
7.10.19Validate cookie expiration is appropriate (no indefinite session cookies)Reasonable expirationMediumDeterministic
7.10.20Validate no sensitive data stored in cookies (tokens should be opaque)No sensitive data in cookie valuesMediumDeterministic

TLS Configuration & Certificate

IDCheckPasses whenWeightRuns
7.10.21Validate TLS version is 1.2 or higher (no TLS 1.0/1.1)TLS >= 1.2HeavyDeterministic
7.10.22Validate certificate chain is complete and validValid certificate chainHeavyDeterministic
7.10.23Validate cipher suite strength (no weak ciphers like RC4, DES, 3DES)Strong ciphers onlyMediumDeterministic

Subresource Integrity & Dependency Audit

IDCheckPasses whenWeightRuns
7.10.24Validate externally loaded scripts have Subresource Integrity (SRI) hashesSRI present on external scriptsHeavyDeterministic
7.10.25Validate externally loaded stylesheets have SRI hashesSRI present on external stylesheetsHeavyDeterministic
7.10.26Detect public-facing JavaScript libraries with known CVE vulnerabilitiesNo known-vulnerable librariesMediumDeterministic
7.10.27Validate number of third-party scripts is reasonable (not > 30)Third-party script count controlledMediumDeterministic

API Exposure Audit

IDCheckPasses whenWeightRuns
7.10.28Detect API endpoints unintentionally exposed to the public (common with Next.js, Express, Laravel)No unintended public API endpointsHeavyDeterministic
7.10.29Validate exposed API endpoints require authentication or rate limitingAuth or rate limiting presentMediumDeterministic
7.10.30Compute Advanced Security Trust Signals composite scoreFinalizedMediumDeterministic

← 7.9 URL Parameter Sanitization7.11 Secret Leak Detection →

Run these checks on your site

A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.

See plans

Machine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).