Security Audit
15/100
Astra Health ScoreSecurity Audit Results
We detected suboptimal or unsafe practices on your website. Please see the list below for more details.
-
Csp Header Invalid Best Practice Medium
Description:Content Security Policy (CSP) header cannot be parsed successfully.
-
Cookies Samesite Flag Invalid Best Practice Medium
Description:Cookies use SameSite flag, but set to something other than Strict or Lax.
-
Referrer Policy Unsafe Best Practice Medium
Description:Referrer-Policy header set unsafely to "origin", "origin-when-cross-origin", or "unsafe-url".
-
Hsts Not Implemented Best Practice Medium
Description:HTTP Strict Transport Security (HSTS) header not implemented.
-
Sri Not Implemented But External Scripts Loaded Securely Best Practice Medium
Description:Subresource Integrity (SRI) not implemented, but all external scripts are loaded over HTTPS.
-
X Xss Protection Disabled Best Practice Medium
Description:X-XSS-Protection header set to "0" (disabled).