NODE249 TOOLS · LEARN
Learn
Clear explanations of what we check: what it is, why it matters, common mistakes and how we verify it.
- TLS certificates & HTTPSWhat a TLS certificate is, why it expires and how to check your HTTPS is configured correctly.
- Redirect HTTP to HTTPSWhy your site should always redirect http:// to https:// and how to avoid mixed content.
- HSTS (Strict-Transport-Security)What HSTS is, which max-age to use and how to enable it without breaking your site.
- Content-Security-Policy (CSP)What a CSP is, why unsafe-inline weakens it and how to start with a restrictive policy.
- Security headersThe basic HTTP security headers: nosniff, Referrer-Policy, Permissions-Policy and hiding the server version.
- Web accessibilityWhat automated accessibility tests (axe-core) detect, what they do not, and the most common mistakes.
- Cookies & consentWhich cookies and trackers a website loads before consent and why it matters.
- Third-party requestsWhich external services your website contacts when loading, why you should know them and how to reduce them.