Home / Check catalog / 7. Security & Privacy / 7.5 Security Headers

7.5 Security Headers

30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.

Core Security Headers — Presence & Validation

IDCheckPasses whenWeightRuns
7.5.01Validate Content-Security-Policy (CSP) presentPresentCriticalDeterministic
7.5.02Validate CSP blocks inline scripts unless hashedBlockedCriticalDeterministic
7.5.03Validate X-Frame-Options set to DENY or SAMEORIGINSecureHeavyDeterministic
7.5.04Validate X-Content-Type-Options set to nosniffnosniffHeavyDeterministic
7.5.05Validate Referrer-Policy set securely (e.g., strict-origin-when-cross-origin)SecureHeavyDeterministic
7.5.06Validate Permissions-Policy configured (camera, mic, location)ConfiguredMediumDeterministic
7.5.07Validate Strict-Transport-Security (HSTS) enabledEnabledMediumDeterministic
7.5.08Detect missing X-XSS-Protection fallback headerPresent (legacy)MediumDeterministic
7.5.09Validate headers apply uniformly across routesUniformMediumDeterministic
7.5.10Compute Core Security Header Presence ScoreFinalizedCriticalDeterministic

CSP Quality — Directive Hardening, Allowlists & Source Policies

IDCheckPasses whenWeightRuns
7.5.11Validate CSP uses restrictive default-srcRestrictiveHeavyDeterministic
7.5.12Detect wildcard sources * in CSPNoneHeavyDeterministic
7.5.13Validate script-src includes nonce or hashPresentHeavyDeterministic
7.5.14Validate frame-src restrictedRestrictedMediumDeterministic
7.5.15Validate connect-src does not allow open-ended domainsControlledMediumDeterministic
7.5.16Detect policy conflicts that break functionalityNoneMediumDeterministic
7.5.17Validate reporting endpoints configured (report-uri or report-to)ConfiguredMediumDeterministic
7.5.18Validate unsafe-inline not used unless hashedNoneMediumDeterministic
7.5.19Validate CSP syntax error-freeCleanMediumDeterministic
7.5.20Compute CSP Strength & Hardening ScoreFinalizedCriticalDeterministic

Attack Surface Reduction — Hardening Effectiveness & Header Synergy

IDCheckPasses whenWeightRuns
7.5.21Validate clickjacking protections fully activeActiveHeavyDeterministic
7.5.22Validate MIME sniffing protections activeActiveHeavyDeterministic
7.5.23Detect inconsistent header behavior on dynamic pagesNoneHeavyDeterministic
7.5.24Validate CORS rules consistent with security headersConsistentMediumDeterministic
7.5.25Validate outdated legacy headers removedRemovedMediumDeterministic
7.5.26Detect duplicate header declarationsNoneMediumDeterministic
7.5.27Validate cookies protected via Secure + HttpOnly + SameSiteProtectedMediumDeterministic
7.5.28Validate security headers do not break critical UXNo breakageMediumDeterministic
7.5.29Validate preflight (OPTIONS) responses include relevant security headersIncludedMediumDeterministic
7.5.30Compute Attack Surface Reduction Master ScoreFinalizedCriticalDeterministic

← 7.4 Cookie Consent, GDPR & Privacy Metadata7.6 Bot Mitigation & AI/Bot Access Control →

Run these checks on your site

A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.

See plans

Machine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).