Skip to content
Back to HTTP Security Headers

HTTP Security Headers

ilo.org

ilo.org has 10 of 10 security headers correctly configured — strong configuration that ranks in the top tier of the public scan corpus.

200 https://ilo.org/
10 present 0 missing (critical) 0 missing (recommended)
HeaderValueNote
Content-Security-Policydefault-src 'none'; manifest-src 'self'; worker-src 'self...Prevents XSS and injection attacks
Strict-Transport-Securitymax-age=31536000; includeSubDomainsForces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-Policystrict-origin-when-cross-originControls referrer information
Permissions-Policyaccelerometer=(), autoplay=(self "https://www.youtube.com...Controls browser features
X-XSS-Protection0Legacy XSS filter (deprecated)
Cross-Origin-Opener-Policysame-origin; report-to="default"Isolates browsing context
Cross-Origin-Embedder-Policyunsafe-none;report-to="default"Controls cross-origin embedding
Cross-Origin-Resource-Policysame-originControls cross-origin resources

Content-Security-Policy Details

manifest-src 'self'
script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://js-agent.newrelic.com https://bam.nr-data.net https://connect.facebook.net https://platform.twitter.com https://embedr.flickr.com https://widgets.flickr.com https://www.youtube.com https://player.vimeo.com/api/player.js https://*.vimeocdn.com https://p.trellocdn.com https://*.clarity.ms https://s.go-mpulse.net https://datawrapper.dwcdn.net https://public.flourish.studio https://static.cloudflareinsights.com https://www.google-analytics.com/analytics.js https://w.soundcloud.com/player/api.js
style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://platform.twitter.com https://cdnjs.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com https://vjs.zencdn.net https://pt.dwcdn.net https://datawrapper.dwcdn.net https://public.flourish.studio
form-action 'self'
frame-src 'self' https://*.soundcloud.com https://*.dwcdn.net https://*.x.com https://*.tiktok.com https://*.walls.io https://www.youtube.com https://www.youtube-nocookie.com https://*.youku.com https://youtu.be https://www.facebook.com https://*.instagram.com https://*.linkedin.com https://trello.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.flickr.com https://datawrapper.dwcdn.net https://www.googletagmanager.com https://public.flourish.studio https://flo.uri.sh
frame-ancestors 'self'
connect-src 'self' https://www.google.com https://www.googletagmanager.com https://*.google-analytics.com https://maps.googleapis.com https://embedr.flickr.com https://vimeo.com https://bam.nr-data.net https://*.clarity.ms https://c.go-mpulse.net https://datawrapper.dwcdn.net https://public.flourish.studio
report-uri https://ilopublic.report-uri.com/r/d/csp/enforce
worker-src 'self'
img-src 'self' data: https://www.googletagmanager.com https://fonts.gstatic.com https://geoservices.un.org https://i.ytimg.com https://syndication.twitter.com https://pbs.twimg.com https://embedr.flickr.com https://*.staticflickr.com https://*.vimeocdn.com https://*.vimeo.com https://*.clarity.ms https://c.bing.com https://static.dwcdn.net https://datawrapper.dwcdn.net https://public.flourish.studio
media-src 'self' data:
child-src 'self' https://*.soundcloud.com https://*.dwcdn.net https://*.x.com https://*.tiktok.com https://*.walls.io https://www.youtube.com https://www.youtube-nocookie.com https://*.youku.com https://youtu.be https://www.facebook.com https://*.instagram.com https://*.linkedin.com https://trello.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.flickr.com https://datawrapper.dwcdn.net https://public.flourish.studio
font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com https://static.dwcdn.net
upgrade-insecure-requests
default-src 'none'
base-uri 'self'
object-src 'none'
Show all response headers (37)
Referrer-Policy: strict-origin-when-cross-origin
X-Request-Id: v-63e07f88-994a-11f1-841c-bb181324804d
Cf-Cache-Status: DYNAMIC
X-Ah-Environment: prod
X-Drupal-Dynamic-Cache: HIT
Content-Type: text/html; charset=UTF-8
Last-Modified: Sun, 16 Aug 2026 06:57:58 GMT
Date: Sun, 16 Aug 2026 18:29:48 GMT
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cross-Origin-Embedder-Policy: unsafe-none;report-to="default"
Connection: keep-alive
X-Content-Type-Options: nosniff
X-Consumer-Id: default_consumer
Cross-Origin-Resource-Policy: same-origin
X-Xss-Protection: 0
Cross-Origin-Opener-Policy: same-origin; report-to="default"
X-Permitted-Cross-Domain-Policies: none
Via: varnish
Report-To: {'group':'default','max_age':31536000,'endpoints':[{'url':'https://ilopublic.report-uri.com/a/d/g '}],'include_subdomains':true}
Cf-Ray: a2c281af3c46bb87-CDG
Surrogate-Key: sgka 2qb4 fa8f 2b3q qrj0 9mud ecpb 54ls p0qp 1a50 rcsn tqnm tut3 ibth jbl8 aj6m 5d41 v0k1 1lpr 068n 7dv9 45fp 8ljl hrlq f3l1 r76k ebf6 bp1k jg68 gq0d flpt kt1n burn 5ksb jd76 8p05 nfur takt r93a 4cv4 uk7q pmql h643 7h23 dthf qhbh d93v 0o0m ni16 1oi1 7l8l k4ld 4c22 8u7p kkb1 r9kl vns9 q5mg rqsa 1bl0 ohe6 9jek 883u ha27 pkbl mcb7 80a3 3q1a pn8p klve sd17 16co ofkg ggnj gh35 7h4t 9005 rkij ca5r hon2 qf6p aj4e mlot g7ob qn8v hm2i a2us cq7i bqtu 8un4 vcuj l6oj 7pnd jvin qq4g ereh 6ck8 9776 7ri3 ihgp 0103 n5ec 6325 i44p gn3h 425u 752l bl2k p42m 5okr dmkf agdq
Age: 36967
X-Drupal-Cache: HIT
X-Geo-Country: FR
X-Cache: HIT
Server: cloudflare
Permissions-Policy: accelerometer=(), autoplay=(self "https://www.youtube.com/embed"), camera=(), clipboard-read=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
Expires: Sun, 19 Nov 1978 05:00:00 GMT
X-Cache-Hits: 249
Content-Security-Policy: default-src 'none'; manifest-src 'self'; worker-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://js-agent.newrelic.com https://bam.nr-data.net https://connect.facebook.net https://platform.twitter.com https://embedr.flickr.com https://widgets.flickr.com https://www.youtube.com https://player.vimeo.com/api/player.js https://*.vimeocdn.com https://p.trellocdn.com https://*.clarity.ms https://s.go-mpulse.net https://datawrapper.dwcdn.net https://public.flourish.studio https://static.cloudflareinsights.com https://www.google-analytics.com/analytics.js https://w.soundcloud.com/player/api.js; object-src 'none'; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://platform.twitter.com https://cdnjs.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com https://vjs.zencdn.net https://pt.dwcdn.net https://datawrapper.dwcdn.net https://public.flourish.studio; img-src 'self' data: https://www.googletagmanager.com https://fonts.gstatic.com https://geoservices.un.org https://i.ytimg.com https://syndication.twitter.com https://pbs.twimg.com https://embedr.flickr.com https://*.staticflickr.com https://*.vimeocdn.com https://*.vimeo.com https://*.clarity.ms https://c.bing.com https://static.dwcdn.net https://datawrapper.dwcdn.net https://public.flourish.studio; media-src 'self' data:; form-action 'self'; frame-src 'self' https://*.soundcloud.com https://*.dwcdn.net https://*.x.com https://*.tiktok.com https://*.walls.io https://www.youtube.com https://www.youtube-nocookie.com https://*.youku.com https://youtu.be https://www.facebook.com https://*.instagram.com https://*.linkedin.com https://trello.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.flickr.com https://datawrapper.dwcdn.net https://www.googletagmanager.com https://public.flourish.studio https://flo.uri.sh; frame-ancestors 'self'; child-src 'self' https://*.soundcloud.com https://*.dwcdn.net https://*.x.com https://*.tiktok.com https://*.walls.io https://www.youtube.com https://www.youtube-nocookie.com https://*.youku.com https://youtu.be https://www.facebook.com https://*.instagram.com https://*.linkedin.com https://trello.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.flickr.com https://datawrapper.dwcdn.net https://public.flourish.studio; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com https://static.dwcdn.net; connect-src 'self' https://www.google.com https://www.googletagmanager.com https://*.google-analytics.com https://maps.googleapis.com https://embedr.flickr.com https://vimeo.com https://bam.nr-data.net https://*.clarity.ms https://c.go-mpulse.net https://datawrapper.dwcdn.net https://public.flourish.studio; base-uri 'self'; report-uri https://ilopublic.report-uri.com/r/d/csp/enforce; upgrade-insecure-requests
X-Frame-Options: SAMEORIGIN
Set-Cookie: __cf_bm=6I3_v6CqOMrYPQ_hli8WcbNR4ytPLnYJcz_XPIDiIeU-1786904988.0327504-1.0.1.1-asKNcs35ORJkW_J2KOI.Nsd82ad2ZPjkDo__hkoOrMlEgJ17aifVvsxTfStn1r1OC0UUm0NHAh7bBTYh2BMFd1lJ8_ZLhBfqU3vD1oZMhn6EAJFnowF5oDGO6ikyHdsb; HttpOnly; SameSite=None; Secure; Path=/; Domain=ilo.org; Expires=Sun, 16 Aug 2026 18:59:48 GMT
Cache-Control: max-age=86400, public
Content-Language: en
Vary: Cookie,X-Consumer-ID,Accept-Encoding,X-Geo-Country
Alt-Svc: h3=":443"; ma=86400
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=42

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for ilo.org

Share this result: