Loading…
Security Audit
https://www.sitevitals.co.uk/asset_check_test_page.html
Public Share Link
Anyone with this link can view this dashboard. Link expires in 24 hours.
Security Score
Excellent
Good posture. Fix the remaining issues below to reach full compliance.
Headers, JavaScript, software & more
Top priorities
1 issue foundIssues with the most impact on your site's security.
Iframe integrity
One or more iframe findings require review.
Iframe integrity
One or more iframe findings require review.
Content Guardian (CSP)
Your guard is active, but it uses "unsafe-inline" or "unsafe-eval". To meet 2026 security standards, consider implementing cryptographic Nonces to lock down your scripts further.
Old-School Script Filter (XSS)
This older safety check is missing. This is not critical as long as your "Content Guardian (CSP)" is robust.
Device & Feature Privacy
No policy detected; by default, the site could request access to a user's camera, location, or biometric sensors.
HTTP to HTTPS Redirect
Site automatically redirects insecure traffic to HTTPS.
Legacy URL Scripts
No "javascript:" URLs were found in your links.
Encoded Script Detection
No encoded script bypasses detected.
Hexadecimal Masking
No hex-obfuscated code was found.
Base64 Masking
No Base64-encoded scripts were detected.
Execution Safety (eval)
The dangerous "eval()" function is not being used.
Inline Action Triggers
Your site uses secure, modern event listeners separated from your HTML.
Suspicious Inline Code
No suspicious inline code patterns were found.
Safe Timers (setTimeout)
Timers are being used safely with function references.
Safe Loops (setInterval)
Repeating timers are configured securely.
Dynamic Function Safety
No dynamic function constructors are in use.
Page Writing Safety
Modern, safe page update methods are being used.
Cloudflare
Up to date
Enforced Encryption (HSTS)
Encrypted connections are strictly enforced for 2026 compliance.
Data Leakage Protection
Your visitors’ data stays private when they leave your site.
Clickjack Protection
Your site cannot be invisible-framed by others. Your interface belongs to you.
File Type Sniffing
Browsers are forced to respect the actual file type, preventing "mime-sniffing" attacks.
Automatic Redirects
No forced auto-redirects found.
Mixed Content Check
All resources are loaded securely over HTTPS.
Wordpress
Version not detected; unable to compare against latest or check for vulnerabilities.
Sign up for free
Get free uptime checking, full reports for SEO and AI, page speed, and regression alerts.
Get Started for FreeReady to unlock full access?