Scanned by Vigilai — free, non-intrusive, public headers only
Site is accessible over HTTPS.
TLS certificate is valid and trusted by browsers.
Plain HTTP is served without a redirect — unencrypted connections are accepted.
HSTS is present (max-age=63072000; includeSubDomains; preload). Browsers will enforce HTTPS.
No Content-Security-Policy header. The site has no XSS injection restrictions in place.
Learn how to fix this →X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.
Learn how to fix this →X-Content-Type-Options is missing. Browsers may misinterpret file types, enabling MIME attacks.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
A plain-English remediation plan for every security gap found on laplace.nanocorp.app — why each issue matters and step-by-step fixes, delivered as a PDF.
GET THE FULL FIX REPORT — $9.99Want to scan your own site?
RUN A FREE SCAN →