Skip to content
Back to HTTP Security Headers

HTTP Security Headers

nrdc.org

nrdc.org has 3 of 10 security headers correctly configured, most notably Content-Security-Policy — addressing the critical findings flagged below will move it into the strong tier.

200 https://nrdc.org/
3 present 1 missing (critical) 1 missing (recommended)
HeaderValueNote
Content-Security-PolicyNot setPrevents XSS and injection attacks
Strict-Transport-Securitymax-age=31536000, preloadForces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-PolicyNot setControls referrer information
Permissions-PolicyNot setControls browser features
X-XSS-ProtectionNot setLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources
Show all response headers (25)
X-Content-Type-Options: nosniff
Connection: keep-alive
Last-Modified: Fri, 14 Aug 2026 23:23:08 GMT
Surrogate-Control: max-age=3600, public, stale-while-revalidate=86400, stale-if-error=86400
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=377
X-Platform-Server: i-050025012a0a426fa4f4ccf5f71d4a10
X-Platform-Server: i-050025012a0a426fa4f4ccf5f71d4a10
Surrogate-Key: QkJj 7G8f H5fw 9C7v IxbF DZnx 18bJ PwY+ CJWa xTnv M4i0 ccQP 3NOC J7s1 IaoW 6+yy ZbX+ dLUt 0lqZ Ow// wcKb 7P5g WWwZ Dhq7 668q Vpqx MldO w1IJ 4PAA r288 m/Mu fXBn Yup/ O82o tx0W xqYs FB8M tGBV c/yk wK9J ZoNp dpb6 laZW UX/9 D6vY z4YP 14qV jIK2 KAxc rsv/ AGtt iLVq oJCG hW3n 0lXl 7zcD 4jFy XzwA E2iF gGbs LOL7 3EDz UJPW GDZR n14A r626 zI7U 7bop QWxk oGvc Dsnv Pgz8 NTA4 RhOi gHMl SAM7 qCmL et32 Gwy+ 12T3 HVSW J8l4 xLob wT8v ZxGk fmkY dBUC 8QzE O3MY /S0H G+HC B4qx eHZw fdTJ HrEH lw6i Yshd CzAP f0RI 5QoV D2Aw X0cN uHDV rnLx 5S5k 5rHU yicE Ez6m CLhP zgVq ejO0 zC73 uv4Q ErLX AJsk MH41 /1z+ nK/n 8AaP yYQt TqI4 3uZo xzUS R8UG mrd0 7lrN SpxT BNw+ nvgU 3gFO aGze WVb+ IXBd boNH Eu5H ROgW PO54 yIyb Ma45 /WQA 7I6+ jy17 WwtX 2UR1 2j68 F8KB Br+F t/9o R5t4 xwfW myoV q0VW 9zpD tWDI tDYg Mb0p XCbc wW5x HFMd Cnrh ldB1 l6se HWOG bMCz LXq6 tKT3 I7iO WmNY z1qC bi9o uulv t2I8 ob9N Cf7s zLVB hcU6 vKss foTh YMRc ZPUq OWJo YSum 1R5o F7XF p3Z1 3X7L 1BVN DAFJ eoWC nBnP 8yQQ r41U i7vA xqDL ZXBt ifBc Zyc7 irMH CdAo d3Ya
Content-Security-Policy-Report-Only: connect-src 'self' cdn.cookielaw.org geolocation.onetrust.com ipmeta.io *.abtasty.com www.google-analytics.com www.googletagmanager.com stats.g.doubleclick.net *.widencdn.net *.yimg.com *.stackadapt.com *.bing.com *.snapchat.com *.facebook.com *.tiktok.com *.tiktokw.us *.nrdcapi.org https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' www.googletagmanager.com ad.ipredictive.com *.snapchat.com *.doubleclick.net trk.clinch.co *.youtube.com *.youtube-nocookie.com; img-src 'self' cdn.cookielaw.org *.abtasty.com data: www.nrdc.org *.doubleclick.net *.widencdn.net *.google.com *.facebook.com *.linkedin.com *.bing.com *.snapchat.com *.yahoo.com trkn.us *.tiktok.com *.tiktokw.us *.widen.net https://www.google-analytics.com https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' bat.bing.com cdn.cookielaw.org code.jquery.com connect.facebook.net data: googleads.g.doubleclick.net js.ipredictive.com platform.instagram.com platform.twitter.com qvdt3feo.com s.yimg.com snap.licdn.com tags.srv.stackadapt.com blob: *.abtasty.com www.googletagmanager.com www.instagram.com cdn.jsdelivr.net cdnjs.cloudflare.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' agadata.online apis.google.com bat.bing.com cdn.cookielaw.org code.jquery.com colegiodiocesanosantaclara.imtlazarus.com:6443 connect.facebook.net data1.blamap.com get663.com googleads.g.doubleclick.net js.ipredictive.com lf16-tiktok-web.tiktokcdn-us.com nrdcapps.org pixel.byspotify.com platform.instagram.com platform.twitter.com public.tableau.com qvdt3feo.com s.yimg.com sc-static.net snap.licdn.com tags.srv.stackadapt.com translate-pa.googleapis.com translate.google.com translate.googleapis.com try.abtasty.com www.google-analytics.com www.googletagmanager.com www.instagram.com www.nrdcapps.org www.pagespeed-mod.com www.scrible.com www.tiktok.com unpkg.com www.vimeo.com www.youtube.com www.tp88trk.com apps.rokt.com *.mountain.com analytics.tiktok.com tr.snapchat.com cdn.clinch.co cdn.jsdelivr.net cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' cdn.honey.io tags.srv.stackadapt.com www.gstatic.com *.abtasty.com cdn.jsdelivr.net fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' blob: cdn.honey.io lf16-tiktok-web.tiktokcdn-us.com nrdcapps.org sf16-website-login.neutral.ttwstatic.com tags.srv.stackadapt.com www.googletagmanager.com www.gstatic.com www.nrdcapps.org www.scrible.com cdn.jsdelivr.net fonts.googleapis.com; worker-src 'self' blob:; frame-ancestors 'self'; report-uri https://nrdc.report-uri.com/r/d/csp/wizard
Traceresponse: 00-18cc58de5f62f035558de71ff21dcd2f-4e739147e9887fc4-01
X-Debug-Info: eyJyZXRyaWVzIjowfQ==
X-Drupal-Dynamic-Cache: HIT
Date: Sun, 16 Aug 2026 17:21:04 GMT
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Content-Language: en
Cf-Cache-Status: DYNAMIC
X-Generator: Drupal 10 (https://www.drupal.org)
Server: cloudflare
Content-Type: text/html; charset=UTF-8
Cache-Control: max-age=3600, public
X-Frame-Options: SAMEORIGIN
Fastly-Drupal-Html: YES
Vary: Cookie
Cf-Ray: a2c21cff98d199fa-CDG
Strict-Transport-Security: max-age=31536000, preload
X-Drupal-Cache: HIT

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for nrdc.org

Share this result: