FREE SECURITY SCAN RESULTS

weather.gov

Scanned by Vigilai — free, non-intrusive, public headers only

A
Excellent
SECURITY GRADE
weather.gov
7PASSED
1WARNINGS
0FAILED
1 ISSUE DETECTED
Get a prioritized, plain-English fix report for all your issues — $9.99
GET FIX REPORT — $9.99
HTTPS ReachablePASS

Site is accessible over HTTPS.

TLS CertificatePASS

TLS certificate is valid and trusted by browsers.

HTTP→HTTPS RedirectPASS

HTTP traffic is automatically redirected to HTTPS.

HSTSPASS

HSTS is present (max-age=31536000 ; includeSubDomains ; preload). Browsers will enforce HTTPS.

Content Security PolicyPASS

Content-Security-Policy is present, reducing the risk of cross-site scripting.

!
X-Frame-OptionsWARN

X-Frame-Options is missing. The page can be embedded in iframes, enabling clickjacking.

Learn how to fix this →
X-Content-Type-OptionsPASS

X-Content-Type-Options: nosniff is set. MIME-sniffing attacks are blocked.

Referrer PolicyPASS

Referrer-Policy is "no-referrer". Controls what URL data is shared with third parties.

1 ISSUE TO FIX

Get the $9.99 full fix report

A plain-English remediation plan for every security gap found on weather.gov — why each issue matters and step-by-step fixes, delivered as a PDF.

GET THE FULL FIX REPORT — $9.99
One-time payment · Instant delivery · No subscription

Want to scan your own site?

RUN A FREE SCAN →
Checks: HTTPS, TLS, HTTP redirect, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-PolicyNon-intrusive · GET requests only · vigilai.nanocorp.app/scan