pardot.comHTTP Security Headers Checker

Check for Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and other critical security headers.

Last checked: Mar 18, 2026, 08:00 PM UTC

35/100
Grade D

Scan Results

Security Headers Score35/100
0
Critical
3
High
1
Medium
4
Passed

Common Security Headers Issues

  • No Content-Security-Policy header
  • Missing X-Frame-Options (clickjacking risk)
  • No X-Content-Type-Options: nosniff
  • Overly permissive CORS headers
  • Missing Referrer-Policy

What This Check Covers

HTTP security headers are directives sent by the server that instruct browsers how to handle content. Missing headers are one of the most common — and easiest to fix — web security vulnerabilities. Tools like securityheaders.com and ShipSafer check for their presence and correct configuration.

  • Content-Security-Policy (CSP)
  • X-Frame-Options (clickjacking protection)
  • X-Content-Type-Options: nosniff
  • Referrer-Policy
  • Permissions-Policy
  • Strict-Transport-Security (HSTS)
  • Cross-Origin Resource Policy (CORP)

Why it matters

Missing security headers are responsible for a wide range of attacks: clickjacking, XSS, MIME-type sniffing, and information leakage. They take minutes to add and can prevent entire vulnerability classes.

Get the full security report for pardot.com

SSL, headers, CORS, cookies, DNS + 60 more checks — free