What it checks
Browser protections
The instructions your site gives a visitor's browser to keep them safe.
How it is checked
Sentinel reads the headers and cookies your site sends with its pages, and looks through each page for parts loaded without encryption.
- Security headers. The protective headers sent with your home page.
- Cookies. The flags on each cookie your site sets.
- Mixed content. Scripts, frames and images loaded over plain HTTP from encrypted pages.
What it can find
Browsers are not told to always use encryption
Worth tidyingGood practice that is missing.
- What it is
- Your site does not send the header that tells browsers to use HTTPS every time, even if a link or a person asks for the plain version.
- Why it matters
- Without it, the first moment of a visit can happen unencrypted, which is enough for someone on the same network to interfere.
- How to fix it
- Add the Strict-Transport-Security header in the web server or hosting settings.WordPress: most security plugins and many hosts have a switch for HSTS. On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
No limit on which scripts your pages may run
Worth tidyingGood practice that is missing.
- What it is
- Your site does not send a content security policy, the header that tells browsers which scripts and other content are allowed on your pages.
- Why it matters
- If an attacker ever manages to inject a script into a page, nothing stops the browser from running it.
- How to fix it
- Add a Content-Security-Policy header that lists where scripts, styles and frames may come from. This takes testing: a policy that is too strict breaks the site.On hosted builders this usually cannot be set. It is a lower priority than everything above it.
Other sites can display yours inside their own pages
Worth tidyingGood practice that is missing.
- What it is
- Nothing tells browsers to refuse to show your site inside a frame on someone else's page.
- Why it matters
- A fake page can put your real site in an invisible frame and trick a signed-in visitor into clicking things on it.
- How to fix it
- Add the X-Frame-Options header with the value SAMEORIGIN in the web server or hosting settings.
Browsers may guess at file types
Worth tidyingGood practice that is missing.
- What it is
- Your site does not send the header that stops browsers from guessing what kind of file they received.
- Why it matters
- A file uploaded as an image could be treated as a script by some browsers.
- How to fix it
- Add the X-Content-Type-Options header with the value nosniff in the web server or hosting settings.
Full page addresses are shared with sites you link to
Worth tidyingGood practice that is missing.
- What it is
- Your site does not set a referrer policy, so browsers decide how much of a page's address to pass on when a visitor follows a link out.
- Why it matters
- Addresses can contain private details, such as an order number or a reset link.
- How to fix it
- Add the Referrer-Policy header in the web server or hosting settings.
A cookie can be sent without encryption
Should fixMakes an attack easier or more damaging.
- What it is
- Your site sets a cookie without the Secure flag, so a browser will also send it over a plain HTTP connection.
- Why it matters
- If the cookie keeps someone signed in, anyone who sees it on the network can use it to become that person.
- How to fix it
- Set the Secure flag where the cookie is created. For a platform's own cookies this is usually a setting, and serving the whole site over HTTPS is a prerequisite.
A sign-in cookie can be read by scripts
Should fixMakes an attack easier or more damaging.
- What it is
- A cookie that looks like it keeps visitors signed in is set without the HttpOnly flag, so any script on the page can read it.
- Why it matters
- If a malicious script ever runs on your site, it can copy the cookie and take over the visitor's session.
- How to fix it
- Set the HttpOnly flag where the cookie is created.
An encrypted page loads a script or frame without encryption
Should fixMakes an attack easier or more damaging.
- What it is
- A page served over HTTPS pulls in a script, stylesheet or frame over plain HTTP.
- Why it matters
- Whoever can interfere with that one unencrypted request can change what your page does. Browsers block these, so part of the page may also be broken.
- How to fix it
- Change each http:// address to https://. If the other site does not offer HTTPS, host the file yourself or remove it.WordPress: a search-and-replace of http:// addresses in the database, or a plugin that does it, fixes most of these.
An encrypted page loads images without encryption
Worth tidyingGood practice that is missing.
- What it is
- A page served over HTTPS loads images or media over plain HTTP.
- Why it matters
- Browsers may show the page as not fully secure, or leave the images out.
- How to fix it
- Change each http:// address to https://.