Skip to content
Back to HTTP Security Headers

HTTP Security Headers

rit.edu

rit.edu has 3 of 10 security headers correctly configured, most notably Content-Security-Policy — addressing the critical findings flagged below will move it into the strong tier.

200 https://rit.edu/
3 present 1 missing (critical) 1 missing (recommended)
HeaderValueNote
Content-Security-PolicyNot setPrevents XSS and injection attacks
Strict-Transport-Securitymax-age=31536000; includeSubDomainsForces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-PolicyNot setControls referrer information
Permissions-PolicyNot setControls browser features
X-XSS-ProtectionNot setLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources
Show all response headers (20)
Content-Language: en
Etag: "1786903420-gzip"
X-Drupal-Cache-Contexts: languages:language_content languages:language_interface route theme timezone url.path url.query_args:_wrapper_format url.site user.node_grants:view user.permissions user.roles
Server: Apache
Content-Type: text/html; charset=UTF-8
X-Generator: Drupal 10 (https://www.drupal.org)
X-Drupal-Cache-Tags: block_content:57 block_content_view block_view config:asset_injector.css.us_and_world_report_badges config:asset_injector.css.us_news_and_world_report_vertical_badges config:asset_injector.js.animate_when_in_viewport_only_after_scroll config:block.block.instagramblock config:block.block.instagramblock_2 config:block.block.mainnavigation config:block.block.mainnavigation_2 config:block.block.openhousebanner config:block.block.purgethispage config:block.block.rit_bootstrap_subtheme_breadcrumbs config:block.block.rit_bootstrap_subtheme_contact_us_webform config:block.block.rit_bootstrap_subtheme_content config:block.block.rit_bootstrap_subtheme_help config:block.block.rit_bootstrap_subtheme_local_actions config:block.block.rit_bootstrap_subtheme_local_tasks config:block.block.rit_bootstrap_subtheme_page_title config:block.block.rit_bootstrap_subtheme_rit_main_menu config:block.block.rit_bootstrap_subtheme_rit_messages config:block.block.rit_bootstrap_subtheme_rit_social_media config:block.block.rit_bootstrap_subtheme_search_form config:block.block.rit_bootstrap_subtheme_site_social_media config:block.block.rit_bootstrap_subtheme_staticlinks config:block.block.viewsexposedfilterblock config:block_list config:extlink.settings config:field.storage.node.body config:field.storage.node.field_image config:field.storage.node.field_subtitle config:filter.format.basic_html config:filter.format.full_html config:filter.format.unfiltered_html config:google_tag.container.primary config:google_tag_container_list config:paragraphs.settings config:system.menu.main config:system.site config:user.role.anonymous config:views.view.areas_of_study config:views.view.faces_of_rit config:views.view.latest_events config:views.view.latest_news_rit_main http_response local_task node:108758 node:108979 node:108999 node:109003 node:109627 node:157723 node:157743 node:1667569 node:1825336 node:1864423 node:209 node:210106 node:2994847 node:321633 node:3393646 node:345630 node:345633 node:345636 node:345639 node:345642 node:345645 node:345648 node:345651 node:345654 node:345657 node:345660 node:345663 node:345669 node:345672 node:345675 node:345678 node:345681 node:345684 node:345690 node:345693 node:345696 node:345699 node:345702 node:345705 node:345711 node:345717 node:345720 node:345726 node:345729 node:345735 node:345738 node:345741 node:345744 node:345747 node:369 node:420155 node:420158 node:420161 node:4676248 node:5080777 node:565143 node:568452 node:568455 node:6217108 node:6217624 node:6220200 node:6220203 node:6220206 node:6220398 node:6269567 node:6271682 node:6271724 node:6287392 node:6287395 node:6343972 node:65681 node:65773 node:65777 node:65785 node:65793 node:65801 node:65809 node:65813 node:65821 node:6602761 node:669023 node:6984512 node:6984713 node:6995504 node:6995510 node:7004786 node:7139384 node:7380680 node:7416882 node:7418025 node:7449171 node:7449621 node:7450577 node:7450940 node:7454339 node:7454342 node:7454345 node:911354 node:919334 node_list node_view paragraph:1089 paragraph:1125 paragraph:1133 paragraph:1201 paragraph:1205 paragraph:1221 paragraph:1245 paragraph:14089 paragraph:14092 paragraph:21870 paragraph:21873 paragraph:22350 paragraph:24431 paragraph:24434 paragraph:25285 paragraph:25288 paragraph:25594 paragraph:35794 paragraph:35797 paragraph:48102 paragraph:48105 paragraph:48108 paragraph:48111 paragraph:50393 paragraph:52097 paragraph:52100 paragraph:52103 paragraph:52814 paragraph:56971 paragraph:7563 paragraph_view rendered taxonomy_term:344509 taxonomy_term:374988 taxonomy_term:4847 taxonomy_term:4851 taxonomy_term:4855 taxonomy_term:4859 taxonomy_term:4863 taxonomy_term:4867 taxonomy_term:4871 taxonomy_term:4875 taxonomy_term:4879 taxonomy_term:4887 taxonomy_term:4891 taxonomy_term_list taxonomy_term_view user:0 user:1 user:165 user:185
X-Drupal-Cache-Max-Age: 0 (Uncacheable)
Strict-Transport-Security: max-age=31536000; includeSubDomains
Last-Modified: Sun, 16 Aug 2026 18:03:40 GMT
Connection: keep-alive
X-Content-Type-Options: nosniff
X-Drupal-Cache: HIT
Date: Sun, 16 Aug 2026 18:20:57 GMT
Cache-Control: max-age=900, public
Vary: Accept-Encoding
X-Frame-Options: SAMEORIGIN
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Age: 585
X-Server: 1i2

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for rit.edu

Share this result: