← Back to the Scoreboard
Site audit · public record

NFL

nfl.com · measured July 19, 2026
1 of 6
security headers present · Failing

Security headers

Six response headers every browser and security scanner checks for. They are set once at the server and cost nothing to add. Anyone can verify this list in about ten seconds with curl.

Strict-Transport-Security
Tells browsers to only ever connect over HTTPS, so a link that starts as http is upgraded before anything is sent.
Present
Content-Security-Policy
Tells the browser which scripts and styles are allowed to run, which is the main defence against injected code.
Absent
X-Content-Type-Options
Stops the browser guessing a file type, which is how a harmless upload can end up executed as a script.
Absent
X-Frame-Options
Stops other sites embedding your pages in a hidden frame to capture clicks meant for you.
Absent
Referrer-Policy
Controls how much of your URL is handed to the next site a visitor clicks through to.
Absent
Permissions-Policy
Declares which browser features, camera, microphone, location, the page is allowed to ask for.
Absent

Performance, SEO and accessibility

Not yet measured for this site. We add these in batches, because unlike the header check they draw on a metered quota. The header result above is complete on its own.

Want these fixed, not just flagged?
We rebuild sites clean, and we do not stop until every category comes back green, including all six security headers, or your money back. You own everything, no lock-in.
← Back to the Scoreboard

We measure a public website only. This says nothing about how NFL handles data internally, and nothing here is a statement about any incident. Headers were read with a single request following redirects on July 19, 2026.