HeaderAudit
B

python.org

Score 80/100 ยท scanned 2026-08-04

Content-Security-Policy

No enforcing Content-Security-Policy on the homepage response. What that means โ†’

Headers sent

HeaderValue
content-security-policy-report-onlyobject-src 'none'; img-src 'self' data:; default-src 'self'; frame-ancestors 'self'; font-src 'self'; base-uri 'self'; connect-src 'self'; script-src 'self'; form-action 'self'; style-src 'self'
strict-transport-securitymax-age=63072000; includeSubDomains; preload
x-frame-optionsSAMEORIGIN
servernginx

Re-scan live

This is a snapshot from 2026-08-04. Check it now: