Skip to content
Back to HTTP Security Headers

HTTP Security Headers

cnil.fr

cnil.fr has 5 of 10 security headers correctly configured, most notably X-Frame-Options — solid but with room to tighten the warnings flagged below.

200 https://cnil.fr/
5 present 0 missing (critical) 1 missing (recommended)
HeaderValueNote
Content-Security-Policydefault-src *.openstreetmap.org *.openlayers.org *.cartoc...Prevents XSS and injection attacks
Strict-Transport-Securitymax-age=63072000; includeSubdomains; preloadForces HTTPS connections
X-Frame-OptionsNot setPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-Policystrict-origin-when-cross-originControls referrer information
Permissions-PolicyNot setControls browser features
X-XSS-Protection1; mode=blockLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources

Content-Security-Policy Details

font-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
object-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
form-action 'self' *.signal-spam.fr *.cnil.fr *.economie.gouv.fr
style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
img-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr data:
frame-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
frame-ancestors 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
block-all-mixed-content
base-uri 'self'
default-src *.openstreetmap.org *.openlayers.org *.cartocdn.com *.arcgisonline.com 'self' data: blob:
script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
script-src-elem 'self' data: 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr
Show all response headers (25)
Cache-Control: max-age=31536000, public
Cache-Control: private
Vary: Cookie,Accept-Encoding
Cf-Cache-Status: DYNAMIC
Cache-Tags: HIT
Purge-Cache-Tags: config:block_list config:block.block.bootstrap_cnil_system_main config:block.block.cnil_plaintes_sending_form config:block.block.plaintes_steps config:block.block.bootstrap_cnil_tabs config:block.block.branding config:block.block.header_menu_en config:block.block.header_menu_part_fr config:block.block.header_menu_pro_fr config:block.block.menu_header config:block.block.menu_header_en_2 config:block.block.search config:block.block.top_nav config:block.block.topnav config:block.block.user_space_switcher config:block.block.breadcrumbs config:block.block.footer_menu_en config:block.block.footer_menu_part_fr config:block.block.footer_menu_pro_fr config:block.block.menu_footer config:block.block.menu_footer_en config:block.block.menu_footer_policy config:block.block.menu_footer_policy_en config:block.block.menu_footer_sitemap config:block.block.menu_footer_sitemap_en config:block.block.menu_utilitaire_en config:block.block.newsletter config:matomo.settings block_view config:system.menu.menu-menu-footer node:84679 node:84677 node:9573 node:84655 node:745 config:system.menu.menu-menu-utilitaire node:84640 node:1180 node:190 paragraph_view paragraph:6475 config:paragraphs.settings file:294192 file:3534207 file:3270697 file:3502932 file:943 file:3533481 file:3535215 file:3535002 paragraph:107 file:3501624 paragraph:12852 file:3483320 paragraph:12681 file:93045 paragraph:104 config:filter.format.full_html media:2528 paragraph:103 media:2516 paragraph:102 media:2519 user:1 local_task CACHE_MISS_IF_UNCACHEABLE_HTTP_METHOD:form config:system.site config:color.theme.bootstrap_cnil config:system.menu.top-nav rendered http_response config:user.role.anonymous config:system.menu.header-part-fr node:163997 node:1026 node:1128 node:858 node:164015 node:166257 node:164012 node:164033 node:165258 node:164009 node:164042 node:164039 node:9101 node:166046 node:164606 node:1191 node:1348 node:522 node:519 node:520 node:1347 node:1143 node:1343 node:1345 node:1344 node:911 node:855 node:404 node:83655 node:9124 node:8812 node:1190 node:1186 node:1187 node:1188 node:1189 node:1053 node:1101 node:589 taxonomy_term:76 taxonomy_term:79 node:1176 node:168034 node:168037 node:167037 node:163534 node:871 taxonomy_term:72 media_view media:1137 config:image.style.menu_header_thumbnail file:1533 media:2318 file:26804
Date: Sun, 16 Aug 2026 18:32:27 GMT
X-Xss-Protection: 1; mode=block
Content-Security-Policy: default-src *.openstreetmap.org *.openlayers.org *.cartocdn.com *.arcgisonline.com 'self' data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; script-src-elem 'self' data: 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; img-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr data:; font-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; object-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; frame-src 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr; frame-ancestors 'self' *.openstreetmap.org *.openlayers.org *.cartocdn.com *.cnil.fr ; form-action 'self' *.signal-spam.fr *.cnil.fr *.economie.gouv.fr ; block-all-mixed-content; base-uri 'self'
Expires: Sun, 19 Nov 1978 05:00:00 GMT
X-Content-Type-Options: nosniff
X-Varnish: 105126567 124426719
Strict-Transport-Security: max-age=63072000; includeSubdomains; preload
X-Drupal-Cache: HIT
Server: cloudflare
Content-Language: fr
Via: 1.1 varnish (Varnish/7.1)
X-Drupal-Dynamic-Cache: UNCACHEABLE (poor cacheability)
Connection: keep-alive
Last-Modified: Sun, 16 Aug 2026 18:19:39 GMT
Set-Cookie: SERVERID=dvs19821.eva.produhost.net; path=/
Content-Type: text/html; charset=UTF-8
Referrer-Policy: strict-origin-when-cross-origin
X-Generator: Drupal 10 (https://www.drupal.org)
Age: 214
Cf-Ray: a2c2859519a9f0f4-CDG

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for cnil.fr

Share this result: