Skip to content
SitesProof
Security headers and TLS

Six headers, one handshake, per page.

Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy — reported where they are absent, and graded higher when the page takes card details.

The problem

The certificate expires on a Saturday

Headers get set once, during a build, and then a host migration or a new CDN quietly drops them. A certificate renews automatically for two years and then does not. Neither of these is hard to see — they are just invisible until a client calls, and nobody is checking forty hosts by hand on a Monday.

How it works

How security headers and tls works

  1. 1

    Per page, on real responses

    Only pages that returned a normal 200: a 404’s headers are the error page’s headers, so checking them would report the wrong thing about the wrong page.

  2. 2

    One handshake per host

    From a single TLS connection to the site’s main host: HTTPS not available at all, a certificate expired or expiring within 30 days, an outdated protocol version, a hostname that does not match, a chain that does not validate.

  3. 3

    Reported as absence, never as a verdict

    A missing header is a missing header. Header values are never judged, so tightening a Content-Security-Policy does not churn the finding, and nothing here says a site is secure or insecure.

Why it matters

What you get

The payment page counts for more

A missing Content-Security-Policy on a page that takes card details is graded higher than the same absence on a blog post, and it names PCI DSS 6.4.3 — because that is the page the requirement is about.

Expiry you hear about in advance

Thirty days of notice on a leaf certificate, every week, across the whole portfolio. Certificate Transparency logs are watched alongside it, so a certificate nobody expected turning up is recorded too.

Honest grading

Most missing headers are low or medium with no standard attached, because that is what they are. A check that graded a missing Permissions-Policy as critical would teach you to ignore the severity column.

Start with one page.

Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.

Scan a page free