Six response headers every browser and security scanner checks for. They are set once at the server and cost nothing to add. Anyone can verify this list in about ten seconds with curl.
✓
Strict-Transport-Security
Tells browsers to only ever connect over HTTPS, so a link that starts as http is upgraded before anything is sent.
Present
✓
Content-Security-Policy
Tells the browser which scripts and styles are allowed to run, which is the main defence against injected code.
Present
✕
X-Content-Type-Options
Stops the browser guessing a file type, which is how a harmless upload can end up executed as a script.
Absent
✕
X-Frame-Options
Stops other sites embedding your pages in a hidden frame to capture clicks meant for you.
Absent
✕
Referrer-Policy
Controls how much of your URL is handed to the next site a visitor clicks through to.
Absent
✕
Permissions-Policy
Declares which browser features, camera, microphone, location, the page is allowed to ask for.
Absent
Performance, SEO and accessibility
Not yet measured for this site. We add these in batches, because unlike the header check they draw on a metered quota. The header result above is complete on its own.
Want these fixed, not just flagged?
We rebuild sites clean, and we do not stop until every category comes back green, including all six security headers, or your money back. You own everything, no lock-in.
We measure a public website only. This says nothing about how TikTok handles data internally, and nothing here is a statement about any incident. Headers were read with a single request following redirects on July 19, 2026.