Skip to content
Back to HTTP Security Headers

HTTP Security Headers

cepal.org

cepal.org has 6 of 10 security headers correctly configured — strong configuration that ranks in the top tier of the public scan corpus.

200 https://cepal.org/
6 present 0 missing (critical) 0 missing (recommended)
HeaderValueNote
Content-Security-Policydefault-src 'self' 'unsafe-inline' https://*.clarity.ms h...Prevents XSS and injection attacks
Strict-Transport-Securitymax-age=31557600Forces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-Policystrict-origin-when-cross-originControls referrer information
Permissions-Policyaccelerometer=(), autoplay=self, bluetooth=(), camera=(),...Controls browser features
X-XSS-ProtectionNot setLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources

Content-Security-Policy Details

connect-src 'self' https://*.cepal.org http://*.cepal.org https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://embedr.flickr.com https://*.googleapis.com http://cdnjs.cloudflare.com/ajax/libs/tagify/ https://www.google-analytics.com https://www.googletagmanager.com
media-src 'self' https://*.cepal.org
object-src 'none'
script-src 'self' 'report-sample' 'unsafe-inline' https://*.googletagmanager.com https://*.googleapis.com https://*.clarity.ms https://c.bing.com cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org
script-src-elem 'self' 'report-sample' 'unsafe-inline' https://*.cepal.org https://www.googletagmanager.com https://www.google-analytics.com https://embedr.flickr.com http://embedr.flickr.com https://widgets.flickr.com https://public.tableau.com https://*.googleapis.com https://*.clarity.ms cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org
script-src-attr 'self' 'report-sample' 'unsafe-inline'
worker-src 'self'
block-all-mixed-content
font-src 'self' https://*.cepal.org https://fonts.gstatic.com https://styles.cepal.org data:
style-src-elem 'self' 'report-sample' 'unsafe-inline' https://*.cepal.org https://*.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org
form-action 'self' https://*.exlibrisgroup.com/
frame-ancestors 'self' https://*.cepal.org
report-uri https://www.cepal.org/es/log-report-uri/enforce
default-src 'self' 'unsafe-inline' https://*.clarity.ms https://c.bing.com
frame-src 'self' https://*.cepal.org https://www.googletagmanager.com https://*.youtube.com https://youtube.com https://player.vimeo.com https://maps.google.com https://public.tableau.com https://online.fliphtml5.com https://e.issuu.com https://view.genially.com/
img-src 'self' data: https://*.cepal.org https://fonts.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.staticflickr.com http://*.staticflickr.com https://public.tableau.com https://www.google-analytics.com https://www.googletagmanager.com
style-src 'self' 'report-sample' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org
style-src-attr 'self' 'report-sample' 'unsafe-inline'
base-uri 'self'
Show all response headers (24)
Etag: W/"1786906515"
Content-Language: es
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31557600
Content-Security-Policy: default-src 'self' 'unsafe-inline' https://*.clarity.ms https://c.bing.com; connect-src 'self' https://*.cepal.org http://*.cepal.org https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://embedr.flickr.com https://*.googleapis.com http://cdnjs.cloudflare.com/ajax/libs/tagify/ https://www.google-analytics.com https://www.googletagmanager.com; font-src 'self' https://*.cepal.org https://fonts.gstatic.com https://styles.cepal.org data:; frame-src 'self' https://*.cepal.org https://www.googletagmanager.com https://*.youtube.com https://youtube.com https://player.vimeo.com https://maps.google.com https://public.tableau.com https://online.fliphtml5.com https://e.issuu.com https://view.genially.com/; img-src 'self' data: https://*.cepal.org https://fonts.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.staticflickr.com http://*.staticflickr.com https://public.tableau.com https://www.google-analytics.com https://www.googletagmanager.com; media-src 'self' https://*.cepal.org; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' https://*.googletagmanager.com https://*.googleapis.com https://*.clarity.ms https://c.bing.com cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org; script-src-attr 'self' 'report-sample' 'unsafe-inline'; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://*.cepal.org https://www.googletagmanager.com https://www.google-analytics.com https://embedr.flickr.com http://embedr.flickr.com https://widgets.flickr.com https://public.tableau.com https://*.googleapis.com https://*.clarity.ms cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org; style-src 'self' 'report-sample' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org; style-src-attr 'self' 'report-sample' 'unsafe-inline'; style-src-elem 'self' 'report-sample' 'unsafe-inline' https://*.cepal.org https://*.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com eclacstrap.ddev.site https://cdnjs.cloudflare.com styles.cepal.org; worker-src 'self'; base-uri 'self'; form-action 'self' https://*.exlibrisgroup.com/; frame-ancestors 'self' https://*.cepal.org; report-uri https://www.cepal.org/es/log-report-uri/enforce; block-all-mixed-content
Content-Security-Policy: frame-ancestors *.cepal.org
X-Forwarded-For: 86.92.235.206, 157.52.109.24, 10.0.40.71
Vary: , Origin, Accept-Encoding
Connection: keep-alive
X-Content-Type-Options: nosniff
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Date: Sun, 16 Aug 2026 20:44:28 GMT
Content-Type: text/html; charset=UTF-8
Last-Modified: Sun, 16 Aug 2026 18:55:15 GMT
X-Cache: HIT
Purge-Cache-Tags: config:block_list config:block.block.eclacstrap_cepal_secondary_local_tasks config:block.block.eclacstrap_cepal_primary_local_tasks config:block.block.eclacstrap_cepal_primary_admin_actions config:block.block.eclacstrap_cepal_config_pages_2 config:block.block.eclacstrap_cepal_config_pages config:block.block.eclacstrap_cepal_socialmedia_2 config:configurable_language_list config:block.block.eclacstrap_cepal_languageswitcher config:block.block.eclacstrap_cepal_site_branding config:block.block.eclacstrap_cepal_menuprincipal config:block.block.eclacstrap_cepal_page_title config:block.block.eclacstrap_cepal_content config:block.block.eclacstrap_cepal__configpages__home_htmlcustom config:block.block.eclacstrap_cepal_messages config:block.block.eclacstrap_cepal_breadcrumbs config:block.block.eclacstrap_cepal_footermenusitemap config:block.block.eclacstrap_cepal_preheaderexternallinks config:block.block.eclacstrap_cepal_socialmedia config:block.block.eclacstrap_cepal_facet_topic config:block.block.eclacstrap_cepal_facet_subtopic config:block.block.eclacstrap_cepal_facet_subsidiarybody config:block.block.eclacstrap_cepal_facet_date config:block.block.eclacstrap_cepal_facet_contenttype config:block.block.eclacstrap_cepal__configpages__globalalert config:google_tag_container_list config:google_tag.container.G-SPMBKHZPHZ.67a8d5792f9893.70315668 user:0 block_view config_pages:6 config_pages_view config:system.menu.menu-footer-sitemap node:44516 node:57342 node:64961 node:69711 node:44514 node:61270 node:56327 node:64958 node:31506 node:29232 node:31505 node:64962 node:44512 node:56324 taxonomy_term:8280 node:44499 node:29319 node:30008 node:66212 config:system.menu.social-media config_pages:8 config:filter.format.raw_html config:page_manager.page.home config_pages_list:home_htmlcustom config_pages:18 config_pages:1 paragraph_view paragraph:7019 config:paragraphs.settings config:views.view.observatories taxonomy_term_list config:field.storage.taxonomy_term.field_image config:field.storage.taxonomy_term.field_redirect taxonomy_term:9037 media:1604 config:image.style.max_325x325 taxonomy_term:9048 media:1149 taxonomy_term:9042 media:1609 taxonomy_term:8299 media:26 taxonomy_term:8387 media:31 taxonomy_term:9041 media:39 taxonomy_term:8303 media:27 taxonomy_term:8458 media:22 taxonomy_term:8182 taxonomy_term:8497 media:35 taxonomy_term:8298 media:2115 taxonomy_term:8189 media:23 taxonomy_term:8388 media:32 taxonomy_term:8495 media:28 taxonomy_term:8496 media:34 taxonomy_term:8172 media:1030 taxonomy_term:9039 media:1606 taxonomy_term:8367 media:24 taxonomy_term:9047 media:2114 taxonomy_term:9038 media:1605 taxonomy_term:9044 media:1611 config_pages:16 paragraph:14993 node:90547 node:90361 node:73672 node:90236 node:86824 node:86366 node:86003 splide:af89fc16800.7 node_view user:39596 paragraph:14930 config:views.view.activities node_list node:90583 node:86808 node:72384 node:90235 node:90530 node:90066 config:field.storage.node.field_course_image config:field.storage.node.field_course_method config:field.storage.node.field_course_type config:field.storage.node.field_event_date config:field.storage.node.field_event_type splide:8da2803ae49.6 user:311 user:39626 CACHE_MISS_IF_UNCACHEABLE_HTTP_METHOD:form paragraph:7015 node:90412 node:90563 node:90558 node:90584 node:90388 node:90060 node:90676 node:90639 splide:9800d14c4e5.8 user:31564 user:39296 user:38834 user:35130 user:3186 user:39622 user:38336 paragraph:15128 splide:b708ab6d693.8 local_task config:system.menu.main config:tb_megamenu.menu_config.main__eclacstrap_cepal config:system.menu.preheader-external-links config:system.site config_pages_list:global_alert rendered page_manager_route_name:page_manager.page_view_home_home-block_display-1 http_response config:user.role.anonymous config:csp.settings library_info config:permissionspolicy.settings
X-Cache-Hits: 0
X-Timer: S1786913068.121784,VS0,VE2
Accept-Ranges: bytes
Referrer-Policy: strict-origin-when-cross-origin
X-Served-By: cache-rtm-ehrd2290051-RTM
Alt-Svc: h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
Permissions-Policy: accelerometer=(), autoplay=self, bluetooth=(), camera=(), ch-ua=(), ch-ua-arch=(), ch-ua-bitness=(), ch-ua-full-version=(), ch-ua-full-version-list=(), ch-ua-mobile=(), ch-ua-model=(), ch-ua-platform=(), ch-ua-platform-version=(), ch-ua-wow64=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=self, geolocation=(), gyroscope=(), hid=(), idle-detection=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
Age: 481
Expires: Sun, 19 Nov 1978 05:00:00 GMT

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for cepal.org

Share this result: