Security Audit
60/100
Astra Health ScoreSecurity Audit Results
We detected suboptimal or unsafe practices on your website. Please see the list below for more details.
-
Csp Not Implemented Best Practice Medium
Description:Content Security Policy (CSP) header not implemented.
-
Cookies Without Secure Flag But Protected By Hsts Best Practice Medium
Description:Cookies set without using the Secure flag, but transmission over HTTP prevented by HSTS.
-
Redirection Off Host From Http Best Practice Medium
Description:Initial redirection from HTTP to HTTPS is to a different host, preventing HSTS.
-
Sri Not Implemented But External Scripts Loaded Securely Best Practice Medium
Description:Subresource Integrity (SRI) not implemented, but all external scripts are loaded over HTTPS.