Skip to content
Back to HTTP Security Headers

HTTP Security Headers

who.int

who.int has 6 of 10 security headers correctly configured — strong configuration that ranks in the top tier of the public scan corpus.

200 https://who.int/
6 present 0 missing (critical) 0 missing (recommended)
HeaderValueNote
Content-Security-Policydefault-src 'self' self watch.4am.ch *.analysis.windows.n...Prevents XSS and injection attacks
Strict-Transport-Securitymax-age=31536000; preloadForces HTTPS connections
X-Frame-OptionsSAMEORIGINPrevents clickjacking
X-Content-Type-OptionsnosniffPrevents MIME sniffing
Referrer-Policyno-referrer-when-downgradeControls referrer information
Permissions-PolicyNot setControls browser features
X-XSS-Protection1; mode=blockLegacy XSS filter (deprecated)
Cross-Origin-Opener-PolicyNot setIsolates browsing context
Cross-Origin-Embedder-PolicyNot setControls cross-origin embedding
Cross-Origin-Resource-PolicyNot setControls cross-origin resources

Content-Security-Policy Details

connect-src 'self' data: accounts.google.com *.google-analytics.com *.gstatic.com https://*.googletagmanager.com https://fndrsp.net https://fndrsp-checkout.net https://*.fundraiseup.com https://*.stripe.com https://*.paypal.com https://*.paypalobjects.com https://pay.google.com https://google.com/pay https://api.addressy.com whpelasticdsta01.blob.core.windows.net whpelasticpsta01.blob.core.windows.net heatmaps.monsido.com tracking.monsido.com frontdoor-l4uikgap6gz3m.azurefd.net whotest.appiancloud.com geocode.arcgis.com tiles.arcgis.com www.arcgis.com services.arcgis.com static.arcgis.com utility.arcgisonline.com js.arcgis.com cdn.jsdelivr.net stats.g.doubleclick.net https://*.dec.sitefinity.com *.nativechat.com *.mktoresp.com *.who.int data.who.int *.who.cloud.sitefinity.com *.clarity.ms dc.services.visualstudio.com whosearch.searchblox.com smartsuggest.searchblox.com m.addthis.com liveapi-cached.yext.com liveapi.yext.com answers.yext-pixel.com wss://westeurope.tts.speech.microsoft.com in.hotjar.com wss://*.hotjar.com *.hotjar.com vc.hotjar.io app.powerbi.com pbi.azureedge.net pbipdfapp.azurewebsites.net wabi-north-europe-redirect.analysis.windows.net *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com kendo.cdn.telerik.com https://*.insight.sitefinity.com
frame-ancestors tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com app.powerbi.com pbi.azureedge.net *.who.int data.who.int *.who.cloud.sitefinity.com appianportals.com 'self'
object-src tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com app.powerbi.com pbi.azureedge.net pbipdfapp.azurewebsites.net wabi-north-europe-redirect.analysis.windows.net *.who.int data.who.int 'self'
script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com *.who.int data.who.int https://cse.google.com clients1.google.com cse.google.com/adsense/search/async-ads.js https://partner.googleadservices.com https://*.fundraiseup.com https://*.stripe.com https://m.stripe.network https://pay.google.com https://google.com/pay https://*.paypal.com https://*.paypalobjects.com https://app-script.monsido.com/v2/monsido-script.js https://heatmaps.monsido.com/ https://tracking.monsido.com/ https://pagecorrect.monsido.com/v1/page-correct.js https://cdn.monsido.com/ 'unsafe-eval' 'unsafe-inline' data: apps.who.int/gho/athena/data/ *.clarity.ms *.doubleclick.net *.eloqua.com *.en25.com *.googletagmanager.com *.jwpcdn.com *.msecnd.net *.nativechat.com *.pingdom.net *.sharethis.com assets.pinterest.com assets.sitescdn.net cdn.ampproject.org cdn.insight.sitefinity.com cdn.jsdelivr.net covidfunding.eiu.com https://dec.azureedge.net/ https://www.youtube.com/iframe_api js.arcgis.com js.hs-analytics.net js.hs-scripts.com kendo.cdn.telerik.com munchkin.marketo.net npmcdn.com public.tableau.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com storage.googleapis.com tagmanager.google.com tiles.arcgis.com utility.arcgisonline.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whosearch.searchblox.com www.arcgis.com www.clarity.ms www.googletagmanager.com www.who.int www.youtube.com youtu.be app-script.monsido.com unpkg.com /js/isotope.pkgd.js https://heatmaps.monsido.com/v1/heatmaps.js https://cdn.insight.sitefinity.com https://player.vimeo.com/api/player.js
img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com self https://*.fundraiseup.com https://ucarecdn.com https://pay.google.com https://google.com/pay https://*.paypalobjects.com tracking.monsido.com iris.who.int tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com cdn.insight.sitefinity.com js.arcgis.com *.nativechat.com *.sharethis.com *.google-analytics.com *.clarity.ms https://delicious.com https://dec.azureedge.net https://apps.who.int https://*.dec.sitefinity.com *.eloqua.com track.hubspot.com stats.g.doubleclick.net *.who.int data.who.int *.who.cloud.sitefinity.com yt3.ggpht.com addthis.com *.googleusercontent.com *.googletagmanager.com script.hotjar.com www.addthis.com log.pinterest.com whosearch.searchblox.com app.powerbi.com pbi.azureedge.net kendo.cdn.telerik.com img.youtube.com *.analytics.google.com *.g.doubleclick.net *.google.com whpelasticdsta01.blob.core.windows.net whpelasticpsta01.blob.core.windows.net whointsfcloudmedia.blob.core.windows.net https://cdn.insight.sitefinity.com
font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: watch.4am.ch https://*.fundraiseup.com https://*.stripe.com tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com *.sharethis.com use.fontawesome.com www.who.int player.4am.ch player.clevercast.com whosearch.searchblox.com script.hotjar.com app.powerbi.com pbi.azureedge.net *.clarity.ms cdn.jsdelivr.net *.who.int data.who.int
frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com https://syndicatedsearch.goog https://www.google.com/ watch.4am.ch https://*.fundraiseup.com https://*.stripe.com https://*.paypal.com https://pay.google.com https://google.com/pay www.ustream.tv https://video.ibm.com *.kunstmatrix.com *.doubleclick.net *.nativechat.com *.sitefinity.cloud *.who.int data.who.int *.who.cloud.sitefinity.com app.powerbi.com app.sli.do apps.who.int assets.pinterest.com covidfunding.eiu.com creativecommons.org experience.arcgis.com html5-player.libsyn.com js.arcgis.com pbi.azureedge.net platform.twitter.com player.4am.ch player.clevercast.com player.vimeo.com vimeo.com public.tableau.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com syndication.twitter.com tiles.arcgis.com utility.arcgisonline.com wabi-north-europe-g-primary-redirect.analysis.windows.net who.maps.arcgis.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whotest.appiancloud.com www.arcgis.com www.youtube.com www.youtube-nocookie.com youtube-nocookie.com https://app.powerbi.com/ https://cdn.fundraiseup.com appianportals.com https://www.googletagmanager.com/
media-src 'self' data: blob: tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com terrance.who.int *.who.int data.who.int *.who.cloud.sitefinity.com
child-src 'self' blob: tiles.arcgis.com www.arcgis.com apps.who.int/gho/athena/data/ services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com https://vimeo.com www.who.int *.who.int data.who.int
default-src 'self' self watch.4am.ch *.analysis.windows.net *.clarity.ms *.nativechat.com *.tts.speech.microsoft.com *.who.int data.who.int *.who.cloud.sitefinity.com answers.yext-pixel.com app.powerbi.com assets.sitescdn.net content.powerapps.com covidfunding.eiu.com dc.services.visualstudio.com gis.azureedge.net js.arcgis.com liveapi.yext.com liveapi-cached.yext.com pbi.azureedge.net pbipdfapp.azurewebsites.net player.4am.ch player.clevercast.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com tiles.arcgis.com utility.arcgisonline.com visuals.azureedge.net wabi-north-europe-redirect.analysis.windows.net westeurope.tts.speech.microsoft.com who.cloudflareaccess.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whotest.appiancloud.com www.arcgis.com www.googleadservices.com iris.who.int kendo.cdn.telerik.com
style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com *.who.int data.who.int self watch.4am.ch 'unsafe-inline' tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com *.sharethis.com cdn.insight.sitefinity.com cdnjs.cloudflare.com https://dec.azureedge.net https://cdn.fundraiseup.com use.fontawesome.com www.who.int player.4am.ch player.clevercast.com whosearch.searchblox.com tagmanager.google.com blob: https://cdn.insight.sitefinity.com
Show all response headers (25)
Last-Modified: Sat, 15 Aug 2026 16:23:46 GMT
Connection: keep-alive
Referrer-Policy: no-referrer-when-downgrade
Etag: "a8ac6657-9093-4331-89b2-bf0994dc74d0"
Cf-Ray: a2c21ee8a8e6c28a-AMS
Server: cloudflare
X-Instance-Name: wn0ldwk000SU3
Alt-Svc: h3=":443"; ma=86400
X-Xss-Protection: 1; mode=block
Sf-Cache-Key: fwt5iLLyvmvDYVwL6skgK1Wb27hJmO53hZVZqnxHscg1
Sf-Cache-Status: HIT
Content-Security-Policy: default-src 'self' self watch.4am.ch *.analysis.windows.net *.clarity.ms *.nativechat.com *.tts.speech.microsoft.com *.who.int data.who.int *.who.cloud.sitefinity.com answers.yext-pixel.com app.powerbi.com assets.sitescdn.net content.powerapps.com covidfunding.eiu.com dc.services.visualstudio.com gis.azureedge.net js.arcgis.com liveapi.yext.com liveapi-cached.yext.com pbi.azureedge.net pbipdfapp.azurewebsites.net player.4am.ch player.clevercast.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com tiles.arcgis.com utility.arcgisonline.com visuals.azureedge.net wabi-north-europe-redirect.analysis.windows.net westeurope.tts.speech.microsoft.com who.cloudflareaccess.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whotest.appiancloud.com www.arcgis.com www.googleadservices.com iris.who.int kendo.cdn.telerik.com; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com *.who.int data.who.int https://cse.google.com clients1.google.com cse.google.com/adsense/search/async-ads.js https://partner.googleadservices.com https://*.fundraiseup.com https://*.stripe.com https://m.stripe.network https://pay.google.com https://google.com/pay https://*.paypal.com https://*.paypalobjects.com https://app-script.monsido.com/v2/monsido-script.js https://heatmaps.monsido.com/ https://tracking.monsido.com/ https://pagecorrect.monsido.com/v1/page-correct.js https://cdn.monsido.com/ 'unsafe-eval' 'unsafe-inline' data: apps.who.int/gho/athena/data/ *.clarity.ms *.doubleclick.net *.eloqua.com *.en25.com *.googletagmanager.com *.jwpcdn.com *.msecnd.net *.nativechat.com *.pingdom.net *.sharethis.com assets.pinterest.com assets.sitescdn.net cdn.ampproject.org cdn.insight.sitefinity.com cdn.jsdelivr.net covidfunding.eiu.com https://dec.azureedge.net/ https://www.youtube.com/iframe_api js.arcgis.com js.hs-analytics.net js.hs-scripts.com kendo.cdn.telerik.com munchkin.marketo.net npmcdn.com public.tableau.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com storage.googleapis.com tagmanager.google.com tiles.arcgis.com utility.arcgisonline.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whosearch.searchblox.com www.arcgis.com www.clarity.ms www.googletagmanager.com www.who.int www.youtube.com youtu.be app-script.monsido.com unpkg.com /js/isotope.pkgd.js https://heatmaps.monsido.com/v1/heatmaps.js https://cdn.insight.sitefinity.com https://player.vimeo.com/api/player.js; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com *.who.int data.who.int self watch.4am.ch 'unsafe-inline' tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com *.sharethis.com cdn.insight.sitefinity.com cdnjs.cloudflare.com https://dec.azureedge.net https://cdn.fundraiseup.com use.fontawesome.com www.who.int player.4am.ch player.clevercast.com whosearch.searchblox.com tagmanager.google.com blob: https://cdn.insight.sitefinity.com; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com self https://*.fundraiseup.com https://ucarecdn.com https://pay.google.com https://google.com/pay https://*.paypalobjects.com tracking.monsido.com iris.who.int tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com cdn.insight.sitefinity.com js.arcgis.com *.nativechat.com *.sharethis.com *.google-analytics.com *.clarity.ms https://delicious.com https://dec.azureedge.net https://apps.who.int https://*.dec.sitefinity.com *.eloqua.com track.hubspot.com stats.g.doubleclick.net *.who.int data.who.int *.who.cloud.sitefinity.com yt3.ggpht.com addthis.com *.googleusercontent.com *.googletagmanager.com script.hotjar.com www.addthis.com log.pinterest.com whosearch.searchblox.com app.powerbi.com pbi.azureedge.net kendo.cdn.telerik.com img.youtube.com *.analytics.google.com *.g.doubleclick.net *.google.com whpelasticdsta01.blob.core.windows.net whpelasticpsta01.blob.core.windows.net whointsfcloudmedia.blob.core.windows.net https://cdn.insight.sitefinity.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: watch.4am.ch https://*.fundraiseup.com https://*.stripe.com tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com *.sharethis.com use.fontawesome.com www.who.int player.4am.ch player.clevercast.com whosearch.searchblox.com script.hotjar.com app.powerbi.com pbi.azureedge.net *.clarity.ms cdn.jsdelivr.net *.who.int data.who.int; frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com https://syndicatedsearch.goog https://www.google.com/ watch.4am.ch https://*.fundraiseup.com https://*.stripe.com https://*.paypal.com https://pay.google.com https://google.com/pay www.ustream.tv https://video.ibm.com *.kunstmatrix.com *.doubleclick.net *.nativechat.com *.sitefinity.cloud *.who.int data.who.int *.who.cloud.sitefinity.com app.powerbi.com app.sli.do apps.who.int assets.pinterest.com covidfunding.eiu.com creativecommons.org experience.arcgis.com html5-player.libsyn.com js.arcgis.com pbi.azureedge.net platform.twitter.com player.4am.ch player.clevercast.com player.vimeo.com vimeo.com public.tableau.com services.arcgis.com staging-dot-eiu-wellcome-7664.nw.r.appspot.com syndication.twitter.com tiles.arcgis.com utility.arcgisonline.com wabi-north-europe-g-primary-redirect.analysis.windows.net who.maps.arcgis.com who-answers.pagescdn.com who-covid-answers.int.pagescdn.com whotest.appiancloud.com www.arcgis.com www.youtube.com www.youtube-nocookie.com youtube-nocookie.com https://app.powerbi.com/ https://cdn.fundraiseup.com appianportals.com https://www.googletagmanager.com/; connect-src 'self' data: accounts.google.com *.google-analytics.com *.gstatic.com https://*.googletagmanager.com https://fndrsp.net https://fndrsp-checkout.net https://*.fundraiseup.com https://*.stripe.com https://*.paypal.com https://*.paypalobjects.com https://pay.google.com https://google.com/pay https://api.addressy.com whpelasticdsta01.blob.core.windows.net whpelasticpsta01.blob.core.windows.net heatmaps.monsido.com tracking.monsido.com frontdoor-l4uikgap6gz3m.azurefd.net whotest.appiancloud.com geocode.arcgis.com tiles.arcgis.com www.arcgis.com services.arcgis.com static.arcgis.com utility.arcgisonline.com js.arcgis.com cdn.jsdelivr.net stats.g.doubleclick.net https://*.dec.sitefinity.com *.nativechat.com *.mktoresp.com *.who.int data.who.int *.who.cloud.sitefinity.com *.clarity.ms dc.services.visualstudio.com whosearch.searchblox.com smartsuggest.searchblox.com m.addthis.com liveapi-cached.yext.com liveapi.yext.com answers.yext-pixel.com wss://westeurope.tts.speech.microsoft.com in.hotjar.com wss://*.hotjar.com *.hotjar.com vc.hotjar.io app.powerbi.com pbi.azureedge.net pbipdfapp.azurewebsites.net wabi-north-europe-redirect.analysis.windows.net *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com kendo.cdn.telerik.com https://*.insight.sitefinity.com; media-src 'self' data: blob: tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com terrance.who.int *.who.int data.who.int *.who.cloud.sitefinity.com; child-src 'self' blob: tiles.arcgis.com www.arcgis.com apps.who.int/gho/athena/data/ services.arcgis.com utility.arcgisonline.com js.arcgis.com *.nativechat.com https://vimeo.com www.who.int *.who.int data.who.int; frame-ancestors tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com app.powerbi.com pbi.azureedge.net *.who.int data.who.int *.who.cloud.sitefinity.com appianportals.com 'self'; object-src tiles.arcgis.com www.arcgis.com services.arcgis.com utility.arcgisonline.com js.arcgis.com app.powerbi.com pbi.azureedge.net pbipdfapp.azurewebsites.net wabi-north-europe-redirect.analysis.windows.net *.who.int data.who.int 'self'
Expires: Sun, 16 Aug 2026 16:20:44 GMT
Access-Control-Expose-Headers: Request-Context
Content-Type: text/html; charset=utf-8
Cache-Control: public, max-age=0, s-maxage=43200
Request-Context: appId=cid-v1:de8aa419-25cb-497c-a74e-dd1c159376e3
X-Content-Type-Options: nosniff
Age: 3698
Vary: accept-encoding
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31536000; preload
Cf-Cache-Status: HIT
Date: Sun, 16 Aug 2026 17:22:22 GMT
Access-Control-Allow-Origin: *

Want the full picture?

This is just one of 100+ checks BeaverCheck runs in a full website audit.

Run Full Audit →

How we grade the results

Each header receives one of three grades: pass (present with a correct, current-best-practice value), warning (present but with a value that is outdated, insufficient, or contains a known weakness), or critical (missing entirely in a context where it should be set). The weighting reflects real-world impact: missing CSP and HSTS on a production HTTPS site are the most severe findings, while a missing Permissions-Policy on a static marketing page is a warning rather than critical. We do not penalize headers that are intentionally absent for a documented reason — for example, X-Frame-Options is now redundant when a CSP frame-ancestors directive is set, and we credit the CSP path. The scoring also adapts to the response: a 301 redirect that ships only the minimum subset of headers is treated differently from a 200 HTML response that should carry the full set. All grading rules are deterministic and visible in the source repository, and the same evaluator runs across both this free tool and the full audit pipeline so results are consistent either way.

Common findings on real sites

Across thousands of public scans, four patterns repeat. First, missing Content-Security-Policy is the most common critical finding — more than half of audited sites ship no CSP at all, leaving inline scripts and event handlers vulnerable to XSS injection. Second, HSTS is often present but configured weakly: a max-age below six months, missing includeSubDomains, or absent from the preload list — meaning the first visit to a subdomain still happens over plaintext. Third, X-Content-Type-Options: nosniff is missing on a surprising number of API responses, allowing MIME-sniffing attacks where a JSON endpoint is reinterpreted as JavaScript by a malicious referring page. Fourth, Permissions-Policy is the newest header and the least adopted: most sites do not deny access to the 10+ powerful browser APIs even when they never use any of them, leaving an XSS-compromised page free to silently activate the user's microphone or geolocation. A site that passes all four checks ends up in the top 5% of the public scan corpus, which is a much stronger signal than a single header grade in isolation.

How to add the missing headers

Most security headers are one line to add. For Nginx, set them in the server or http block with the add_header directive — for example: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always. The 'always' parameter is important — without it, Nginx skips the header on non-200 responses, leaving error pages unprotected. For Apache, use Header set inside a Directory or VirtualHost block. For Express.js, the helmet middleware sets the full security-header set with sensible defaults in three lines: install helmet, require it, and add app.use(helmet()) before any route. For Cloudflare, the Transform Rules dashboard exposes every header without redeploying — useful for setting CSP and HSTS on origins you do not control. The trickiest header is Content-Security-Policy: a wrong value breaks the page silently, so always start in report-only mode (Content-Security-Policy-Report-Only) for at least a week before switching to enforcement. Use the report-uri or report-to directive to collect violation reports, fix what your application legitimately needs, then promote to enforcing mode. The CSP details panel in this tool's report breaks each directive out separately so you can see exactly which sources your site allows today.

Why these headers actually matter

Security headers are the lowest-effort, highest-impact defense most sites can deploy — they cost nothing to add and they neutralize entire classes of attack at the browser boundary, before your application code runs. CSP turns XSS from a near-total compromise into a logged violation report you can investigate at leisure. HSTS prevents the SSL-stripping attacks that defeat HTTPS on hostile networks, including the rogue Wi-Fi access points common at conferences and coffee shops. X-Frame-Options and frame-ancestors block clickjacking, where an attacker embeds your authenticated UI in a transparent iframe and tricks users into clicking destructive actions. The Cross-Origin trio (COOP, COEP, CORP) was added specifically to mitigate Spectre and Meltdown speculative-execution side channels — without them, a malicious cross-origin embed can read your tab's memory through timing attacks. Permissions-Policy is the youngest header but arguably the most important: a single XSS bug in a page that explicitly allows camera access lets an attacker turn the user's webcam on without UI feedback. None of this replaces other defenses (input validation, parameterized queries, dependency hygiene), but it does buy enormous defense-in-depth at near-zero implementation cost.

Other reports for who.int

Share this result: