FlowingDev

セキュリティヘッダー 無料

HTTPレスポンスのセキュリティヘッダーを採点して、直し方まで教えてくれる。 データがこのブラウザの外に出ることはありません。

HTTP レスポンスヘッダー6 lines
F

セキュリティ評価

存在するヘッダーとその値に基づきます。

良好Strict-Transport-Security

max-age=63072000; includeSubDomains

Recommended: max-age of at least 15552000, includeSubDomains, preload

リスクContent-Security-Policy

Add a restrictive policy, e.g. default-src 'self'

良好X-Frame-Options / frame-ancestors

SAMEORIGIN

Use DENY/SAMEORIGIN or CSP frame-ancestors to prevent clickjacking

良好X-Content-Type-Options

nosniff

Recommended: nosniff

リスクReferrer-Policy

Recommended: strict-origin-when-cross-origin

リスクPermissions-Policy

Restrict powerful features, e.g. geolocation=(), camera=()

リスクCross-Origin-Opener-Policy

Recommended: same-origin

リスクServer / X-Powered-By

nginx

Reveals software details; consider removing or genericizing

準備完了