hardened-demo.local
Grade A · scanned in 1.6s
0 critical · 0 warnings · 14 passed · 0 info
https://hardened-demo.localSaved report · permalinkHSTS configured
PassStrict-Transport-Security is set with a max-age of at least one year, which keeps browsers pinned to HTTPS.
max-age=31536000; includeSubDomains
Learn moreContent-Security-Policy set
PassA CSP is configured, limiting which scripts and resources the browser will execute.
default-src 'self'
Learn moreClickjacking protection set
PassX-Frame-Options limits who can embed your site in a frame.
DENY
Learn moreMIME sniffing disabled
Pass`nosniff` is set, preventing browsers from executing files as the wrong type.
nosniff
Learn moreReferrer-Policy set
PassReferrer leakage is controlled by an explicit policy.
strict-origin-when-cross-origin
Learn moreNo server version leaked
PassNeither `Server` nor `X-Powered-By` discloses implementation details.
Modern TLS (TLSv1.3)
PassThe server uses TLS 1.2 or newer, avoiding known protocol weaknesses.
TLSv1.3
Certificate is valid
PassThe certificate is trusted and not near expiry (valid to Wed, 12 May 2027 19:18:48 GMT).
valid_to: Wed, 12 May 2027 19:18:48 GMT
SPF record present
PassAn SPF record is published, telling receivers which servers may send mail for your domain.
v=spf1 -all
DMARC policy enforced (p=reject)
PassDMARC is actively telling receivers how to handle mail that fails authentication.
v=DMARC1; p=reject
DKIM record present
PassA DKIM public key was found, enabling signed email.
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQE
All cookies use security flags
PassAll 1 cookie(s) set Secure, HttpOnly, and SameSite.
No mixed content
PassAll referenced resources on this HTTPS page use secure URLs.
No exposed secrets detected
PassNo known credential patterns were found in the page source.