100/ 100

hardened-demo.local

Grade A · scanned in 1.6s

0 critical · 0 warnings · 14 passed · 0 info

https://hardened-demo.localSaved report · permalink

HSTS configured

Pass

Strict-Transport-Security is set with a max-age of at least one year, which keeps browsers pinned to HTTPS.

max-age=31536000; includeSubDomains

Learn more

Content-Security-Policy set

Pass

A CSP is configured, limiting which scripts and resources the browser will execute.

default-src 'self'

Learn more

Clickjacking protection set

Pass

X-Frame-Options limits who can embed your site in a frame.

DENY

Learn more

MIME sniffing disabled

Pass

`nosniff` is set, preventing browsers from executing files as the wrong type.

nosniff

Learn more

Referrer-Policy set

Pass

Referrer leakage is controlled by an explicit policy.

strict-origin-when-cross-origin

Learn more

No server version leaked

Pass

Neither `Server` nor `X-Powered-By` discloses implementation details.

Modern TLS (TLSv1.3)

Pass

The server uses TLS 1.2 or newer, avoiding known protocol weaknesses.

TLSv1.3

Certificate is valid

Pass

The certificate is trusted and not near expiry (valid to Wed, 12 May 2027 19:18:48 GMT).

valid_to: Wed, 12 May 2027 19:18:48 GMT

SPF record present

Pass

An SPF record is published, telling receivers which servers may send mail for your domain.

v=spf1 -all

DMARC policy enforced (p=reject)

Pass

DMARC is actively telling receivers how to handle mail that fails authentication.

v=DMARC1; p=reject

DKIM record present

Pass

A DKIM public key was found, enabling signed email.

v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQE

All cookies use security flags

Pass

All 1 cookie(s) set Secure, HttpOnly, and SameSite.

How to fix: No action needed.

No mixed content

Pass

All referenced resources on this HTTPS page use secure URLs.

No exposed secrets detected

Pass

No known credential patterns were found in the page source.