Encryption
HTTPS, HSTS, mixed content, form destinations and observed cookie flags.
PASSIVE WEBSITE SECURITY CHECK
N-Secure checks publicly observable protections and maps the results to relevant OWASP Top 10 risk areas. It does not attack the website or attempt to gain access.
HTTPS, HSTS, mixed content, form destinations and observed cookie flags.
Content Security Policy, clickjacking defence and response-header configuration.
Technology disclosure and integrity protection for externally loaded scripts.