Six headers, one handshake, per page.
Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy — reported where they are absent, and graded higher when the page takes card details.
The problem
The certificate expires on a Saturday
Headers get set once, during a build, and then a host migration or a new CDN quietly drops them. A certificate renews automatically for two years and then does not. Neither of these is hard to see — they are just invisible until a client calls, and nobody is checking forty hosts by hand on a Monday.
How it works
How security headers and tls works
- 1
Per page, on real responses
Only pages that returned a normal 200: a 404’s headers are the error page’s headers, so checking them would report the wrong thing about the wrong page.
- 2
One handshake per host
From a single TLS connection to the site’s main host: HTTPS not available at all, a certificate expired or expiring within 30 days, an outdated protocol version, a hostname that does not match, a chain that does not validate.
- 3
Reported as absence, never as a verdict
A missing header is a missing header. Header values are never judged, so tightening a Content-Security-Policy does not churn the finding, and nothing here says a site is secure or insecure.
Why it matters
What you get
The payment page counts for more
A missing Content-Security-Policy on a page that takes card details is graded higher than the same absence on a blog post, and it names PCI DSS 6.4.3 — because that is the page the requirement is about.
Expiry you hear about in advance
Thirty days of notice on a leaf certificate, every week, across the whole portfolio. Certificate Transparency logs are watched alongside it, so a certificate nobody expected turning up is recorded too.
Honest grading
Most missing headers are low or medium with no standard attached, because that is what they are. A check that graded a missing Permissions-Policy as critical would teach you to ignore the severity column.
Features
More features
White-label client reports
One PDF per client per month, carrying your logo, your colours and their name. Nothing in it mentions us except the disclaimer.
Learn morePayment-page scripts
Every script on a page that really takes card details, inventoried and hashed, so a change in the set or in a body is something you hear about.
Learn moreCookies before consent
The crawl loads each site cold, as a first-time visitor, and reports the cookies set and the trackers fired before anyone agreed to anything.
Learn moreStart with one page.
Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.