FlowingDev

Cabeçalhos de segurança Grátis

Dê uma nota nos headers de segurança da sua resposta HTTP, com sugestões de correção. Seus dados nunca saem deste navegador.

CABEÇALHOS HTTP DE RESPOSTA6 lines
F

Nota de segurança

Com base nos cabeçalhos presentes e seus valores.

corretoStrict-Transport-Security

max-age=63072000; includeSubDomains

Recommended: max-age of at least 15552000, includeSubDomains, preload

riscoContent-Security-Policy

Add a restrictive policy, e.g. default-src 'self'

corretoX-Frame-Options / frame-ancestors

SAMEORIGIN

Use DENY/SAMEORIGIN or CSP frame-ancestors to prevent clickjacking

corretoX-Content-Type-Options

nosniff

Recommended: nosniff

riscoReferrer-Policy

Recommended: strict-origin-when-cross-origin

riscoPermissions-Policy

Restrict powerful features, e.g. geolocation=(), camera=()

riscoCross-Origin-Opener-Policy

Recommended: same-origin

riscoServer / X-Powered-By

nginx

Reveals software details; consider removing or genericizing

Pronto