Skip to content

What it checks

Browser protections

The instructions your site gives a visitor's browser to keep them safe.

How it is checked

Sentinel reads the headers and cookies your site sends with its pages, and looks through each page for parts loaded without encryption.

  • Security headers. The protective headers sent with your home page.
  • Cookies. The flags on each cookie your site sets.
  • Mixed content. Scripts, frames and images loaded over plain HTTP from encrypted pages.

What it can find

Browsers are not told to always use encryption

Worth tidying

Good practice that is missing.

What it is
Your site does not send the header that tells browsers to use HTTPS every time, even if a link or a person asks for the plain version.
Why it matters
Without it, the first moment of a visit can happen unencrypted, which is enough for someone on the same network to interfere.
How to fix it
Add the Strict-Transport-Security header in the web server or hosting settings.WordPress: most security plugins and many hosts have a switch for HSTS. On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

No limit on which scripts your pages may run

Worth tidying

Good practice that is missing.

What it is
Your site does not send a content security policy, the header that tells browsers which scripts and other content are allowed on your pages.
Why it matters
If an attacker ever manages to inject a script into a page, nothing stops the browser from running it.
How to fix it
Add a Content-Security-Policy header that lists where scripts, styles and frames may come from. This takes testing: a policy that is too strict breaks the site.On hosted builders this usually cannot be set. It is a lower priority than everything above it.

Other sites can display yours inside their own pages

Worth tidying

Good practice that is missing.

What it is
Nothing tells browsers to refuse to show your site inside a frame on someone else's page.
Why it matters
A fake page can put your real site in an invisible frame and trick a signed-in visitor into clicking things on it.
How to fix it
Add the X-Frame-Options header with the value SAMEORIGIN in the web server or hosting settings.

Browsers may guess at file types

Worth tidying

Good practice that is missing.

What it is
Your site does not send the header that stops browsers from guessing what kind of file they received.
Why it matters
A file uploaded as an image could be treated as a script by some browsers.
How to fix it
Add the X-Content-Type-Options header with the value nosniff in the web server or hosting settings.

Full page addresses are shared with sites you link to

Worth tidying

Good practice that is missing.

What it is
Your site does not set a referrer policy, so browsers decide how much of a page's address to pass on when a visitor follows a link out.
Why it matters
Addresses can contain private details, such as an order number or a reset link.
How to fix it
Add the Referrer-Policy header in the web server or hosting settings.

An encrypted page loads a script or frame without encryption

Should fix

Makes an attack easier or more damaging.

What it is
A page served over HTTPS pulls in a script, stylesheet or frame over plain HTTP.
Why it matters
Whoever can interfere with that one unencrypted request can change what your page does. Browsers block these, so part of the page may also be broken.
How to fix it
Change each http:// address to https://. If the other site does not offer HTTPS, host the file yourself or remove it.WordPress: a search-and-replace of http:// addresses in the database, or a plugin that does it, fixes most of these.

An encrypted page loads images without encryption

Worth tidying

Good practice that is missing.

What it is
A page served over HTTPS loads images or media over plain HTTP.
Why it matters
Browsers may show the page as not fully secure, or leave the images out.
How to fix it
Change each http:// address to https://.

See which of these your own website has.

Start free trial