FREE SECURITY SCAN RESULTS

va.gov

Scanned by Vigilai — free, non-intrusive, public headers only

A
Excellent
SECURITY GRADE
va.gov
5PASSED
3WARNINGS
0FAILED
3 ISSUES DETECTED
Get a prioritized, plain-English fix report for all your issues — $9.99
GET FIX REPORT — $9.99
HTTPS ReachablePASS

Site is accessible over HTTPS.

TLS CertificatePASS

TLS certificate is valid and trusted by browsers.

HTTP→HTTPS RedirectPASS

HTTP traffic is automatically redirected to HTTPS.

HSTSPASS

HSTS is present (max-age=31536000; includeSubDomains; preload). Browsers will enforce HTTPS.

!
Content Security PolicyWARN

No Content-Security-Policy header. The site has no XSS injection restrictions in place.

Learn how to fix this →
X-Frame-OptionsPASS

X-Frame-Options is set to "SAMEORIGIN". Iframe-based clickjacking is blocked.

!
X-Content-Type-OptionsWARN

X-Content-Type-Options is missing. Browsers may misinterpret file types, enabling MIME attacks.

!
Referrer PolicyWARN

Referrer-Policy is not set. Full URLs may be leaked to third-party sites via the Referer header.

3 ISSUES TO FIX

Get the $9.99 full fix report

A plain-English remediation plan for every security gap found on va.gov — why each issue matters and step-by-step fixes, delivered as a PDF.

GET THE FULL FIX REPORT — $9.99
One-time payment · Instant delivery · No subscription

Want to scan your own site?

RUN A FREE SCAN →
Checks: HTTPS, TLS, HTTP redirect, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-PolicyNon-intrusive · GET requests only · vigilai.nanocorp.app/scan