HeaderAudit
C

torproject.org

Score 60/100 · scanned 2026-08-04

Content-Security-Policy

torproject.org sends an enforcing CSP. It is nonce-based.

default-src 'self'; img-src 'self' data:; script-src 'self' 'sha256-J/tux0AP4WAYsCxprPoE+2XJ+XNJ8Esd8nCF8o/diiw='; style-src 'self' 'unsafe-inline';
DirectiveSources
default-src'self'
img-src'self' data:
script-src'self' 'sha256-J/tux0AP4WAYsCxprPoE+2XJ+XNJ8Esd8nCF8o/diiw='
style-src'self' 'unsafe-inline'

Headers sent

HeaderValue
strict-transport-securitymax-age=15768000; preload
x-frame-optionssameorigin
x-content-type-optionsnosniff
referrer-policyno-referrer
x-xss-protection1
serverApache

Re-scan live

This is a snapshot from 2026-08-04. Check it now: