Security carries the largest single weighting in the Index — a site that fails here is exposed regardless of how well it performs elsewhere. These 17 checks cover what's observable from the public HTTP surface: response headers, transport security, and cross-origin policy. They're not a substitute for penetration testing, but they catch the misconfigurations that cause the most real-world breaches.
Grounded in the OWASP Top 10 (2021) and IETF/W3C specs — RFC 6797 (HSTS), RFC 7034 (X-Frame-Options), W3C CSP Level 3, W3C SRI.
Full citation mapping:
Standards & Methodology →
What's checked
- Transport security — HSTS, HSTS preload, HTTPS enforcement, mixed content
- Content security — CSP presence and quality, SRI, X-Frame-Options
- Cross-origin policy — COOP/COEP/CORP, CORS wildcard checks
- Information disclosure — server headers, X-Powered-By
- Cookie security — Secure/HttpOnly/SameSite flags
- Disclosure — security.txt (RFC 9116)
25 points. 17 checks. One published framework.
Security Posture is one of five pillars on the Site Integrity Index. Every check on this page maps to a published standard.
Run your Site Integrity score →