Developer Upgrades Security Header Grader to Distinguish Report-Only CSP and Add TLS Checks
A developer improved an automated security-header grading tool after a commenter pointed out that pass/fail scores without context can be misleading. The original tool treated Content-Security-Policy and Content-Security-Policy-Report-Only identically, meaning a policy not yet enforcing any blocks received the same score as a fully active one. The update also exposed a broader gap: HTTP headers cannot reveal whether a site's TLS certificate is valid, near expiry, or negotiating a weak protocol version. To address this, live TLS handshake inspection was added as an opt-in feature behind a query flag, keeping default audits fast while allowing deeper checks on request. Both fixes — Report-Only-aware CSP grading and optional TLS inspection — have been shipped to the developer's public API.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in