HTTP security headers
Browsers expect specific headers to defend against script injection, clickjacking, and session theft. We check the standard set.
$ curl -I https://example.comHTTP/2 200content-type: text/htmlstrict-transport-security: ?content-security-policy: ?