C
torproject.org
Score 60/100 · scanned 2026-08-04Content-Security-Policy
torproject.org sends an enforcing CSP. It is nonce-based.
default-src 'self'; img-src 'self' data:; script-src 'self' 'sha256-J/tux0AP4WAYsCxprPoE+2XJ+XNJ8Esd8nCF8o/diiw='; style-src 'self' 'unsafe-inline';
| Directive | Sources |
|---|---|
default-src | 'self' |
img-src | 'self' data: |
script-src | 'self' 'sha256-J/tux0AP4WAYsCxprPoE+2XJ+XNJ8Esd8nCF8o/diiw=' |
style-src | 'self' 'unsafe-inline' |
Headers sent
| Header | Value |
|---|---|
strict-transport-security | max-age=15768000; preload |
x-frame-options | sameorigin |
x-content-type-options | nosniff |
referrer-policy | no-referrer |
x-xss-protection | 1 |
server | Apache |
Re-scan live
This is a snapshot from 2026-08-04. Check it now: