No failed or warning checks in this snapshot.
Top 100 .gov Website Security Header Ranking
Vigilai scanned the highest-ranked scannable .gov domains from Tranco’s public top-sites list and ranked them by the same public security-header checks used by the free scanner.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
No failed or warning checks in this snapshot.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Could not check HTTP redirect — port 80 may be blocked or the server is unavailable.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Could not check HTTP redirect — port 80 may be blocked or the server is unavailable.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
X-Content-Type-Options is missing. Browsers may misinterpret file types, enabling MIME attacks.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
HTTP returned status 301. Redirect behaviour is ambiguous.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
HTTP returned status 301. Redirect behaviour is ambiguous.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Could not check HTTP redirect — port 80 may be blocked or the server is unavailable.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
HTTP returned status 404. Redirect behaviour is ambiguous.
HTTP returned status 400. Redirect behaviour is ambiguous.
HTTP returned status 301. Redirect behaviour is ambiguous.
HTTP returned status 302. Redirect behaviour is ambiguous.
HTTP returned status 301. Redirect behaviour is ambiguous.
Could not check HTTP redirect — port 80 may be blocked or the server is unavailable.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.
Strict-Transport-Security header is absent. Browsers won't enforce HTTPS on future visits.