Mozilla Launches Free Website Security Testing Service

BoraMurdar

Community Manager
Thread author
Verified
Staff Member
Well-known
Aug 30, 2012
6,598
Mozilla security engineer April Knight released a project called Observatory, a free website security scanning utility, similar to SSL Labs and High-Tech Bridge's scanning service.

The service, working on top of a Python codebase made available on GitHub, has been under development for months and was approved for a public launch only yesterday.

Observatory is aimed at developers, system administrators, and security professionals that want to configure sites to use modern security protocols.

Service uses A to F scores to grade website security
Observatory scans for the presence of basic security features and then gives out a grade from 0 to 130, which is then converted into an A to F score.

In its current form, the service scans for the following: [1] Content Security Policy (CSP) status, [2] cookie files using Secure flag, [3] Cross-Origin Resource Sharing (CORS) status, [4] HTTP Public Key Pinning (HPKP) status, [5] HTTP Strict Transport Security (HSTS) status, [6] the presence of an automatic redirection from HTTP to HTTPS, [7] Subresource Integrity (SRI) status, [8] X-Content-Type-Options status, [9] X-Frame-Options (XFO) status, and [10] X-XSS-Protection status.

More at Softpedia
 

askmark

Level 12
Verified
Top Poster
Well-known
Aug 31, 2016
578
Thanks for sharing info about this very useful tool. Just checked the company website and it didn't fare too well. Need to get this addressed asap :eek:
 
  • Like
Reactions: kev216

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top