30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.5.01 | Validate Content-Security-Policy (CSP) present | Present |
| 7.5.02 | Validate CSP blocks inline scripts unless hashed | Blocked |
| 7.5.03 | Validate X-Frame-Options set to DENY or SAMEORIGIN | Secure |
| 7.5.04 | Validate X-Content-Type-Options set to nosniff | nosniff |
| 7.5.05 | Validate Referrer-Policy set securely (e.g., strict-origin-when-cross-origin) | Secure |
| 7.5.06 | Validate Permissions-Policy configured (camera, mic, location) | Configured |
| 7.5.07 | Validate Strict-Transport-Security (HSTS) enabled | Enabled |
| 7.5.08 | Detect missing X-XSS-Protection fallback header | Present (legacy) |
| 7.5.09 | Validate headers apply uniformly across routes | Uniform |
| 7.5.10 | Compute Core Security Header Presence Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.5.11 | Validate CSP uses restrictive default-src | Restrictive |
| 7.5.12 | Detect wildcard sources * in CSP | None |
| 7.5.13 | Validate script-src includes nonce or hash | Present |
| 7.5.14 | Validate frame-src restricted | Restricted |
| 7.5.15 | Validate connect-src does not allow open-ended domains | Controlled |
| 7.5.16 | Detect policy conflicts that break functionality | None |
| 7.5.17 | Validate reporting endpoints configured (report-uri or report-to) | Configured |
| 7.5.18 | Validate unsafe-inline not used unless hashed | None |
| 7.5.19 | Validate CSP syntax error-free | Clean |
| 7.5.20 | Compute CSP Strength & Hardening Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.5.21 | Validate clickjacking protections fully active | Active |
| 7.5.22 | Validate MIME sniffing protections active | Active |
| 7.5.23 | Detect inconsistent header behavior on dynamic pages | None |
| 7.5.24 | Validate CORS rules consistent with security headers | Consistent |
| 7.5.25 | Validate outdated legacy headers removed | Removed |
| 7.5.26 | Detect duplicate header declarations | None |
| 7.5.27 | Validate cookies protected via Secure + HttpOnly + SameSite | Protected |
| 7.5.28 | Validate security headers do not break critical UX | No breakage |
| 7.5.29 | Validate preflight (OPTIONS) responses include relevant security headers | Included |
| 7.5.30 | Compute Attack Surface Reduction Master Score | Finalized |
← 7.4 Cookie Consent, GDPR & Privacy Metadata7.6 Bot Mitigation & AI/Bot Access Control →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).