Paste raw HTTP response headers — from curl -I or the browser network tab — to see which security headers are missing and, just as importantly, which ones are present but set to a value that does nothing. Covers CSP, HSTS, X-Frame-Options, cookie flags, CORS and version disclosure.
marduc812
© 202620260824_1c411cc