SECURITY
What the security score checks
The things an attacker, a browser warning or an audit will notice first. All read from outside, without logging in or scanning the server.
- HTTPS, redirect from HTTP and the HSTS header
- Content Security Policy, clickjacking, MIME sniffing, referrer and permissions headers
- Exposed .git, .env, backup and phpinfo files
- Platform identified only when certain, with the version compared to the current release
- WordPress: XML-RPC and public user listing
- Mixed content on HTTPS pages
- Outdated jQuery with known cross-site scripting issues
- Cookie flags and server version disclosure
