ProductReports

A report you can read in a minute.

One score, then every finding, worst first. No jargon, and no wall of warnings.

Every finding, explained in four steps.

Medium

No Content Security Policy

What we saw

The homepage response carried no content-security-policy header and no equivalent meta tag.

content-security-policy: not sent

What it means

Your app does not tell browsers which scripts are allowed to run on it. A Content Security Policy is a list of trusted sources.

What could happen

If someone manages to inject code into a page, through a comment field, a URL or a compromised dependency, the browser will run it without question.

Who can do it
Someone who found another flaw first
Reaches
Every user
At stake
User accounts and customer data

How we fix it

We add a Content Security Policy tuned to what your app actually loads, starting in report-only mode so nothing breaks while we verify it.

Fix it yourselfWe fix it

Play with the score.

Every finding costs points depending on how serious it is, and your worst finding decides the rating.

Critical−30 each0
High−14 each0
Medium−6 each3
Low−2 each2
78

Fair78 out of 100 · 5 open findings

Share it with one link.

Send it to whoever fixes things for you. They can read it without making an account.

See what your app shows to anyone.

Start with a free check. You don’t even need an account to see your score.