DNS_RESOLUTION · v1.0.0 · DNS
Domain resolves to public addresses
WHAT IT CHECKS That the domain resolves (A/AAAA records) through public resolvers and every address is public.
HOW TO FIX Review the A/AAAA records at your DNS provider.
NODE249 TOOLS · METHODOLOGY v0.3.0
You do not have to trust our score: there is no score. Here is exactly what we check, how, with which limits and in which version.
DNS_RESOLUTION · v1.0.0 · DNS
WHAT IT CHECKS That the domain resolves (A/AAAA records) through public resolvers and every address is public.
HOW TO FIX Review the A/AAAA records at your DNS provider.
DNS_IPV6 · v1.0.0 · DNS
WHAT IT CHECKS Whether the domain publishes IPv6 addresses (AAAA records).
HOW TO FIX If your provider supports it, add AAAA records to serve over IPv6 too.
DNS_CAA · v1.0.0 · DNS
WHAT IT CHECKS Whether CAA records restrict which authorities may issue certificates for the domain (the name and its parent are queried).
HOW TO FIX Add a CAA record for the authority you use (e.g. `0 issue "letsencrypt.org"`).
TLS_AVAILABLE · v1.0.0 · TLS
WHAT IT CHECKS That a TLS connection can be established on port 443.
HOW TO FIX Enable HTTPS on your server or provider (Let’s Encrypt is free).
TLS_CERT_TRUSTED · v1.0.0 · TLS
WHAT IT CHECKS That the certificate is issued by a trusted authority, the chain is complete and it covers the visited name.
HOW TO FIX Install a valid certificate for this name with its full intermediate chain.
LIMITATIONS Validated against the Node.js trust store (Mozilla-equivalent).
TLS_CERT_EXPIRY · v1.0.0 · TLS
WHAT IT CHECKS Days left until the certificate expires.
HOW TO FIX Renew the certificate or automate renewal (e.g. certbot).
TLS_PROTOCOL · v1.0.0 · TLS
WHAT IT CHECKS The TLS version negotiated with a modern client (TLS 1.2 or 1.3 expected).
HOW TO FIX Enable TLS 1.3 and disable legacy versions on your server.
LIMITATIONS Legacy versions (TLS 1.0/1.1) are not probed: only the negotiated one is reported.
HTTP_REACHABLE · v1.0.0 · HTTP
WHAT IT CHECKS The final status code after following redirects.
HOW TO FIX Check why the page does not return 200 (server errors, routes or blocking).
HTTP_TO_HTTPS · v1.0.0 · SECURITY
WHAT IT CHECKS That the http:// version of the site redirects to https://.
HOW TO FIX Configure a permanent (301) redirect from http:// to https://.
HTTP_REDIRECT_CHAIN · v1.0.0 · HTTP
WHAT IT CHECKS Number of redirects until the final page.
HOW TO FIX Link straight to the final URL to avoid unnecessary hops.
HTTP_COMPRESSION · v1.0.0 · HTTP
WHAT IT CHECKS Whether HTML is served compressed (gzip or brotli).
HOW TO FIX Enable gzip or brotli on your web server or CDN.
HTTP_RESPONSE_TIME · v1.0.0 · HTTP
WHAT IT CHECKS Time to first byte of the final page, measured from the NODE249 Tools server.
HOW TO FIX Review caching, server performance or use a CDN.
LIMITATIONS A single measurement from Europe: indicative only.
HTTP_MIXED_CONTENT · v1.0.0 · SECURITY
WHAT IT CHECKS Whether an HTTPS page loads resources (scripts, styles, images, iframes) over http://.
HOW TO FIX Switch those references to https:// or relative paths.
LIMITATIONS Based on the initial HTML (no JavaScript executed). Phase 2 will confirm it with a real browser.
HDR_HSTS · v1.0.0 · SECURITY
WHAT IT CHECKS That HTTPS is announced with HSTS and a max-age of at least 180 days.
HOW TO FIX Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.
HDR_CSP · v1.0.0 · SECURITY
WHAT IT CHECKS Whether a CSP exists and whether it allows `unsafe-inline` or `unsafe-eval` for scripts.
HOW TO FIX Define a restrictive CSP (start with `default-src 'self'`) and avoid unsafe-inline/unsafe-eval.
LIMITATIONS A missing CSP is not a vulnerability by itself: it reduces the impact of other flaws.
HDR_XCTO · v1.0.0 · SECURITY
WHAT IT CHECKS That `X-Content-Type-Options: nosniff` is sent.
HOW TO FIX Add `X-Content-Type-Options: nosniff`.
HDR_REFERRER_POLICY · v1.0.0 · PRIVACY
WHAT IT CHECKS That the site defines what referrer information is shared when navigating to other sites.
HOW TO FIX Add `Referrer-Policy: strict-origin-when-cross-origin`.
HDR_PERMISSIONS_POLICY · v1.0.0 · PRIVACY
WHAT IT CHECKS That browser features (camera, microphone, geolocation…) the site may use are restricted.
HOW TO FIX Add `Permissions-Policy` disabling what you do not use (e.g. `camera=(), microphone=(), geolocation=()`).
HDR_CLICKJACKING · v1.0.0 · SECURITY
WHAT IT CHECKS That embedding the site in foreign frames is prevented (`X-Frame-Options` or CSP `frame-ancestors`).
HOW TO FIX Add `Content-Security-Policy: frame-ancestors 'self'` or `X-Frame-Options: SAMEORIGIN`.
HDR_VERSION_DISCLOSURE · v1.0.0 · SECURITY
WHAT IT CHECKS Whether the `Server` or `X-Powered-By` headers reveal software and version.
HOW TO FIX Hide the version (e.g. `server_tokens off` in nginx) and remove `X-Powered-By`.
LIMITATIONS Showing the version does not mean it is vulnerable: it only eases reconnaissance.
A11Y_AUTOMATED · v1.0.0 · ACCESSIBILITY
WHAT IT CHECKS Overall result of automated accessibility tests (axe-core) on the page and a small sample of the same site.
HOW TO FIX Review each listed issue: usually alt text, contrast, form labels or heading structure.
LIMITATIONS Automated tests detect only part of accessibility issues. Full conformance (e.g. WCAG 2.1 AA) requires manual review.
A11Y_VIOLATION · v1.0.0 · ACCESSIBILITY
WHAT IT CHECKS An axe-core rule failing on one or more elements of the analysed pages.
HOW TO FIX Follow the guide linked in the evidence (helpUrl) and fix the listed elements.
LIMITATIONS Up to 3 elements per page are shown as examples; there may be more.
PRIV_COOKIES_INITIAL · v1.0.0 · PRIVACY
WHAT IT CHECKS Which cookies (name and attributes only, never values) and local storage the site sets on load, before the visitor does anything.
HOW TO FIX Non-essential cookies (analytics, advertising) should not be set until the visitor accepts them.
LIMITATIONS The cookie banner is not interacted with (reject/accept scenarios arrive in Phase 4). Technical assessment, not legal advice.
PRIV_THIRD_PARTIES · v1.0.0 · PRIVACY
WHAT IT CHECKS Which external domains the browser contacts when loading the page (grouped by registrable domain).
HOW TO FIX Check each third party is necessary and declared in your privacy policy.
LIMITATIONS A third party is not a problem in itself (CDN, fonts, payments…): it is information to review.
PRIV_TRACKERS_INITIAL · v1.0.0 · PRIVACY
WHAT IT CHECKS Whether known analytics or advertising domains are contacted before any visitor interaction.
HOW TO FIX Load analytics and advertising only after consent (your CMP should block them until then).
LIMITATIONS Detection based on an in-house list of well-known public domains: not every tracker is detected. Some tools may run in cookieless mode.
BROWSER_RENDER · v1.0.0 · HTTP
WHAT IT CHECKS That the page can be loaded in a real browser (Chromium) for the accessibility and privacy checks.
HOW TO FIX If it fails, check whether the site blocks automated browsers or takes too long to load.