{"grade":"A","gradeCapReason":"Grade capped at A because the Content-Security-Policy contains 'unsafe-inline' and 'unsafe-eval' in the script-src directive. These directives are dangerous and prevent an A+.","gradeCapped":true,"headersMissing":[],"headersPresent":["Strict-Transport-Security","Content-Security-Policy","X-Frame-Options","X-Content-Type-Options","Referrer-Policy","Permissions-Policy"],"myssl":{"advanced":["Cross-Origin-Opener-Policy","Cross-Origin-Embedder-Policy","Cross-Origin-Resource-Policy","X-XSS-Protection","X-Permitted-Cross-Domain-Policies","Cache-Control"],"deeper_score":93,"docs":"https://myssl.info/security-headers/api","https_redirect":true,"note":"Anonymous tier is for occasional checks. Register for higher limits, scheduled monitoring and grade-drop alerts.","report_url":"https://myssl.info/security-headers","summary":"Great \u2014 all core security headers are present. Grade capped at A: the Content-Security-Policy contains 'unsafe-inline' and 'unsafe-eval' in the script-src directive. These directives are dangerous and prevent an A+."},"rawHeaders":{"Cache-Control":"no-cache, no-store, must-revalidate","Connection":"keep-alive","Content-Encoding":"gzip","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https: blob:; connect-src 'self' https: wss:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'","Content-Type":"text/html","Date":"Fri, 31 Jul 2026 16:59:11 GMT","ETag":"W/\"6a4e2be2-299d\"","Last-Modified":"Wed, 08 Jul 2026 10:52:18 GMT","Permissions-Policy":"geolocation=(), microphone=(), camera=()","Referrer-Policy":"strict-origin-when-cross-origin","Server":"nginx","Strict-Transport-Security":"max-age=31536000; includeSubDomains","Transfer-Encoding":"chunked","Vary":"Accept-Encoding","X-Content-Type-Options":"nosniff","X-Frame-Options":"SAMEORIGIN"},"score":90,"summary":{"finalUrl":"https://abby.voxduru.com","grade":"A","headers":{"content-security-policy":"amber","permissions-policy":"green","referrer-policy":"green","strict-transport-security":"green","x-content-type-options":"green","x-frame-options":"green"},"site":"abby.voxduru.com","timestamp":"2026-07-31T16:59:11.623495"},"testsFailed":0,"testsPassed":6,"testsQuantity":6,"upcomingHeaders":[{"description":"Spectre-class side-channel attacks via cross-origin embeds.","header":"Cross-Origin-Embedder-Policy","present":false},{"description":"Cross-origin side-channel attacks (Spectre) and tabnabbing via window.opener.","header":"Cross-Origin-Opener-Policy","present":false},{"description":"Cross-origin resource theft, Spectre-style leaks via cached responses.","header":"Cross-Origin-Resource-Policy","present":false}],"warnings":["Content-Security-Policy contains 'unsafe-inline' in the script-src directive, which is dangerous and undermines most of the protection the policy would otherwise provide against XSS.","Content-Security-Policy contains 'unsafe-eval' in the script-src directive, which is dangerous and permits eval()-based script injection."]}
