Scanned by Vigilai — free, non-intrusive, public headers only
Site is accessible over HTTPS.
TLS certificate is valid and trusted by browsers.
HTTP traffic is automatically redirected to HTTPS.
HSTS is present (max-age=31536000 ; includeSubDomains ; preload). Browsers will enforce HTTPS.
Content-Security-Policy is present, reducing the risk of cross-site scripting.
X-Frame-Options is set to "ALLOW-FROM HTTPS://*.DHS.GOV". Iframe-based clickjacking is blocked.
X-Content-Type-Options: nosniff is set. MIME-sniffing attacks are blocked.
Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.
A plain-English remediation plan for every security gap found on uscis.gov — why each issue matters and step-by-step fixes, delivered as a PDF.
GET THE FULL FIX REPORT — $9.99Want to scan your own site?
RUN A FREE SCAN →