The changes amount to the following. x-xss-protection now "passes" if it's set to 1; mode=block The CSP now fails if it doesn't have either a script-src or a default-src. It now checks for referrer-policy simple mode is available which doesn't use colours, and instead prepends each line with either "Misconfigured", "Good", or "Missing. Useful for automating" |
||
---|---|---|
.. | ||
analyse-headers | ||
catjwt | ||
clickjacking | ||
formtocurl | ||
getCertificate | ||
getNPMVersion | ||
getpaths | ||
tlsversionconnect | ||
verifySSL | ||
webtest |