30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.8.01 | Detect unvalidated query parameters entering cache | None |
| 7.8.02 | Validate canonical URL normalization before caching | Normalized |
| 7.8.03 | Validate cache keys exclude user-controlled headers | Excluded |
| 7.8.04 | Validate Vary headers controlled + sanitized | Controlled |
| 7.8.05 | Detect cache poisoning via Host header manipulation | None |
| 7.8.06 | Detect poisoning via X-Forwarded-* headers | None |
| 7.8.07 | Validate forced HTTPS canonicalization | Enforced |
| 7.8.08 | Detect malformed URL encoding bypasses | None |
| 7.8.09 | Detect cache poisoning risk in legacy endpoints | None |
| 7.8.10 | Compute Cache Input Purity Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.8.11 | Validate origin responses identical for identical requests | Identical |
| 7.8.12 | Detect user-influenced dynamic output entering cache | None |
| 7.8.13 | Validate no cookies affect cached pages | None |
| 7.8.14 | Validate CSP headers present (poison mitigation) | Present |
| 7.8.15 | Validate X-Content-Type-Options enforced | Enforced |
| 7.8.16 | Validate no reflective injection points in HTML | Clean |
| 7.8.17 | Validate templates deterministic (no randomization) | Deterministic |
| 7.8.18 | Detect origin responses differing by header value | None |
| 7.8.19 | Validate cache TTLs appropriate (not overly long) | Appropriate |
| 7.8.20 | Compute Origin Determinism & Safety Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.8.21 | Validate CDN stripping untrusted headers | Stripped |
| 7.8.22 | Validate CDN cache key settings safe | Safe |
| 7.8.23 | Validate edge caching rules consistent | Consistent |
| 7.8.24 | Validate only safe cookies allowed in cache | Allowed |
| 7.8.25 | Detect bypass patterns enabling poisoning | None |
| 7.8.26 | Validate reverse proxy not caching 500/400 responses | Correct |
| 7.8.27 | Detect cache poisoning from multivariate testing flags | None |
| 7.8.28 | Validate ETag behavior consistent | Consistent |
| 7.8.29 | Validate stale-while-revalidate not used insecurely | Secure |
| 7.8.30 | Compute Cache Security & Poisoning Resistance Score | Finalized |
← 7.7 PII Data Exposure Prevention7.9 URL Parameter Sanitization →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).