Skip to content
Back to HTTP Security Headers

HTTP Security Headers

thedailystar.net

thedailystar.net has 4 of 10 security headers correctly configured, most notably Content-Security-Policy — addressing the critical findings flagged below will move it into the strong tier.

200 https://thedailystar.net/
4 present 2 missing (critical) 0 missing (recommended)
HeaderValueNote
Content-Security-PolicyNot setPrevents XSS and injection attacks
Strict-Transport-SecurityNot setForces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-Policystrict-origin-when-cross-originControls referrer information
Permissions-PolicyNot setControls browser features
X-XSS-Protection1; mode=blockLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources
Show all response headers (23)
Cf-Cache-Status: EXPIRED
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
Last-Modified: Sun, 16 Aug 2026 18:52:11 GMT
Purge-Cache-Tags: config:block_list config:block.block.swallow_account_menu config:block.block.swallow_views_block__header_top_news_header_top_news config:block.block.swallow_breadcrumbs config:block.block.swallow_help config:block.block.swallow_main_menu config:block.block.swallow_page_title config:block.block.swallow_syndicate config:block.block.swallow_content config:block.block.swallow_messages config:block.block.swallow_primary_admin_actions config:block.block.swallow_primary_local_tasks config:block.block.swallow_secondary_local_tasks config:block.block.swallow_site_branding config:block.block.swallow_sitebranding node:27 config:block.block.swallow_dfptagpopupbannersnd config:block.block.swallow_dfptagpopupbanner config:block.block.swallow_dfptagpop_up_banner_out_of_page config:block.block.swallow_dfptagpop_up_banner_snd_out_of_page config:block.block.swallow_footer config:block.block.swallow_copyrightblock config:block.block.swallow_socialmediablock config:block.block.swallow_dfpadblock config:block.block.swallow_dfpadblock_2 config:block.block.swallow_dfpadblock_3 config:block.block.swallow_dfpadblock_4 config:block.block.swallow_dfptaghomepage_bottom_sticky_hover config:block.block.swallow_stickyfooteradblock config:block.block.swallow_stickyarticlefooteradblock config:google_analytics.settings block_view config:dfp.settings dfp_tag_view config:system.site node_view config:core.entity_view_display.node.page.default node_list taxonomy_term_list node:4242586 user:34 node:4243266 node:4243931 node:4244911 node:4245746 node:4246511 node:4247356 node:4247811 node:4248751 entity_subqueue:in_case_you_missed_it entity_subqueue_list node:4238491 node:3039691 user:196711 node:4242371 node:1697410 node:4240861 user:196686 node:4237751 node:2221456 node:4237736 node:3871781 node:4242376 node:1277515 node:4239886 user:1 node:4237146 node:3390946 node:1543213 node:1588294 node:4237161 node:3907431 node:4237986 node:1354087 node:4240416 node:1377370 node:4239016 node:4089611 node:4125546 user:157277 node:4240101 node:2087657 user:10261 media_list taxonomy_term:17 node:4238191 user:170736 node:4244231 user:180646 entity_subqueue:feature node:4245206 node:3988261 user:157705 node:4246036 node:4061426 user:193546 node:4246041 node:4070696 user:166851 node:4246936 node:2959241 node:4248201 node:3701511 user:157971 node:4244491 node:3352031 user:159931 node:4249036 node:4069381 node:4249041 node:1907477 node:4245986 node:3696271 node:4249051 node:4248196 node:1742980 node:4248246 node:3446766 user:173036 entity_subqueue:opinion entity_subqueue:business entity_subqueue:sports node:4248231 node:3075091 user:196666 node:4248821 user:196646 node:4248836 user:196661 node:4248901 node:1542610 user:196651 node:4249106 node:1676770 node:4249176 user:167356 node:4249136 node:4249191 node:4249206 node:2457 user:4837 node:4249211 node:4249356 user:35 node:4249361 node:4249366 node:4249371 node:4249376 node:4248256 user:177806 node:4248436 node:4248461 node:4113696 node:4248446 node:4116151 node:4116156 node:4248441 node:4057656 entity_subqueue:spotlight node:56137 node:2509 node:4247766 node:4096931 node:4247076 node:3943796 node:4248481 node:1518190 node:4248366 node:3430461 node:4248391 node:4174351 block_content:531 block_content_view config:core.entity_view_display.block_content.basic.default config:filter.format.full_html entity_subqueue:top_news entity_subqueue:top_news_right node:4248451 node:214 node:4248181 node:3795596 node:4248456 node:3223591 node:4249091 user:4390 node:4249141 user:196631 node:4248991 node:4198416 user:196731 node:4249081 user:196121 node:4249086 user:196721 node:4249231 user:194236 node:4249331 node:4249201 node:4249406 node:4249126 node:4249476 node:4249481 taxonomy_term:283513 taxonomy_term:283525 taxonomy_term:283521 taxonomy_term:283533 taxonomy_term:283717 taxonomy_term:283065 taxonomy_term:283201 taxonomy_term:21 taxonomy_term:283405 taxonomy_term:8 taxonomy_term:4 taxonomy_term:61 taxonomy_term:283721 taxonomy_term:125107 taxonomy_term:2 taxonomy_term:159361 taxonomy_term:283529 taxonomy_term:283285 taxonomy_term:609736 taxonomy_term:283325 taxonomy_term:3 taxonomy_term:36 taxonomy_term:38 taxonomy_term:283137 taxonomy_term:37 taxonomy_term:6 taxonomy_term:628 taxonomy_term:614811 taxonomy_term:287056 taxonomy_term:283269 taxonomy_term:642 taxonomy_term:283445 taxonomy_term:283449 taxonomy_term:286946 taxonomy_term:283469 taxonomy_term:283453 taxonomy_term:283461 taxonomy_term:283457 taxonomy_term:1336956 taxonomy_term:3850 taxonomy_term:686646 taxonomy_term:1336966 taxonomy_term:1336971 taxonomy_term:283197 taxonomy_term:607386 taxonomy_term:283221 taxonomy_term:607401 taxonomy_term:607406 taxonomy_term:5604 taxonomy_term:1519037 taxonomy_term:1442261 taxonomy_term:283541 taxonomy_term:90 taxonomy_term:53 taxonomy_term:530731 config:system.menu.mega-menu rendered http_response config:user.role.anonymous config:system.menu.footer node:4039228 node:4039229 node:4039230 node:4039231 node:4039232 node:4174816 config:system.menu.main taxonomy_term:128134 taxonomy_term:283261 node:4085781 config:entityqueue.entity_queue.header_top config:field.storage.node.field_featured_media config:views.view.header_top_news entity_subqueue:header_top node:4245901 node:4245906 node:4246636 media:1432251 config:image.style.small_80x80 media:1431401 media:1431391
Server: cloudflare
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Date: Sun, 16 Aug 2026 18:52:40 GMT
Connection: keep-alive
Content-Language: en
Referrer-Policy: strict-origin-when-cross-origin
Cache-Control: public, max-age=14400
X-Generator: Drupal 11 (https://www.drupal.org)
X-Drupal-Cache: HIT
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
X-Drupal-Dynamic-Cache: UNCACHEABLE (poor cacheability)
Cf-Ray: a2c2a32b78c599b0-CDG
Alt-Svc: h3=":443"; ma=86400
Vary: Accept-Encoding
Vary: Cookie
Server-Timing: cfCacheStatus;desc="EXPIRED"
Server-Timing: cfEdge;dur=13,cfOrigin;dur=390
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=EQstKtFg2bRzoXWQpX4vegduoWlBZTsSSTc23zQXOR2jnsX7TMmRniIdM%2B4givd8LMLk%2B4yZ24gIP%2B8ck%2B%2Fc8FPj3aKdp9IuPxzWiP%2B9ZCvbfVK2iWZSOPAWcyxJRn808upqzzg2"}]}
Content-Type: text/html; charset=UTF-8
X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for thedailystar.net

Share this result: