NODE249 // TOOLSLAB/002 · EXPERIMENTES

NODE249 TOOLS · METHODOLOGY v0.3.0

Methodology

You do not have to trust our score: there is no score. Here is exactly what we check, how, with which limits and in which version.

PRINCIPLES

DNS ENGINE

DNS_RESOLUTION · v1.0.0 · DNS

Domain resolves to public addresses

WHAT IT CHECKS That the domain resolves (A/AAAA records) through public resolvers and every address is public.

HOW TO FIX Review the A/AAAA records at your DNS provider.

DNS_IPV6 · v1.0.0 · DNS

IPv6 availability

WHAT IT CHECKS Whether the domain publishes IPv6 addresses (AAAA records).

HOW TO FIX If your provider supports it, add AAAA records to serve over IPv6 too.

DNS_CAA · v1.0.0 · DNS

CAA records

WHAT IT CHECKS Whether CAA records restrict which authorities may issue certificates for the domain (the name and its parent are queried).

HOW TO FIX Add a CAA record for the authority you use (e.g. `0 issue "letsencrypt.org"`).

Learn more →

TLS ENGINE

TLS_AVAILABLE · v1.0.0 · TLS

HTTPS available

WHAT IT CHECKS That a TLS connection can be established on port 443.

HOW TO FIX Enable HTTPS on your server or provider (Let’s Encrypt is free).

Learn more →

TLS_CERT_TRUSTED · v1.0.0 · TLS

Certificate is trusted and matches the hostname

WHAT IT CHECKS That the certificate is issued by a trusted authority, the chain is complete and it covers the visited name.

HOW TO FIX Install a valid certificate for this name with its full intermediate chain.

LIMITATIONS Validated against the Node.js trust store (Mozilla-equivalent).

Learn more →

TLS_CERT_EXPIRY · v1.0.0 · TLS

Certificate expiry

WHAT IT CHECKS Days left until the certificate expires.

HOW TO FIX Renew the certificate or automate renewal (e.g. certbot).

Learn more →

TLS_PROTOCOL · v1.0.0 · TLS

Negotiated TLS version

WHAT IT CHECKS The TLS version negotiated with a modern client (TLS 1.2 or 1.3 expected).

HOW TO FIX Enable TLS 1.3 and disable legacy versions on your server.

LIMITATIONS Legacy versions (TLS 1.0/1.1) are not probed: only the negotiated one is reported.

Learn more →

HTTP ENGINE

HTTP_REACHABLE · v1.0.0 · HTTP

Page responds successfully

WHAT IT CHECKS The final status code after following redirects.

HOW TO FIX Check why the page does not return 200 (server errors, routes or blocking).

HTTP_TO_HTTPS · v1.0.0 · SECURITY

HTTP redirects to HTTPS

WHAT IT CHECKS That the http:// version of the site redirects to https://.

HOW TO FIX Configure a permanent (301) redirect from http:// to https://.

Learn more →

HTTP_REDIRECT_CHAIN · v1.0.0 · HTTP

Redirect chain length

WHAT IT CHECKS Number of redirects until the final page.

HOW TO FIX Link straight to the final URL to avoid unnecessary hops.

HTTP_COMPRESSION · v1.0.0 · HTTP

Response compression

WHAT IT CHECKS Whether HTML is served compressed (gzip or brotli).

HOW TO FIX Enable gzip or brotli on your web server or CDN.

HTTP_RESPONSE_TIME · v1.0.0 · HTTP

Time to first byte

WHAT IT CHECKS Time to first byte of the final page, measured from the NODE249 Tools server.

HOW TO FIX Review caching, server performance or use a CDN.

LIMITATIONS A single measurement from Europe: indicative only.

HTTP_MIXED_CONTENT · v1.0.0 · SECURITY

Mixed content

WHAT IT CHECKS Whether an HTTPS page loads resources (scripts, styles, images, iframes) over http://.

HOW TO FIX Switch those references to https:// or relative paths.

LIMITATIONS Based on the initial HTML (no JavaScript executed). Phase 2 will confirm it with a real browser.

Learn more →

HEADERS ENGINE

HDR_HSTS · v1.0.0 · SECURITY

Strict-Transport-Security (HSTS)

WHAT IT CHECKS That HTTPS is announced with HSTS and a max-age of at least 180 days.

HOW TO FIX Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

Learn more →

HDR_CSP · v1.0.0 · SECURITY

Content-Security-Policy

WHAT IT CHECKS Whether a CSP exists and whether it allows `unsafe-inline` or `unsafe-eval` for scripts.

HOW TO FIX Define a restrictive CSP (start with `default-src 'self'`) and avoid unsafe-inline/unsafe-eval.

LIMITATIONS A missing CSP is not a vulnerability by itself: it reduces the impact of other flaws.

Learn more →

HDR_XCTO · v1.0.0 · SECURITY

X-Content-Type-Options

WHAT IT CHECKS That `X-Content-Type-Options: nosniff` is sent.

HOW TO FIX Add `X-Content-Type-Options: nosniff`.

Learn more →

HDR_REFERRER_POLICY · v1.0.0 · PRIVACY

Referrer-Policy

WHAT IT CHECKS That the site defines what referrer information is shared when navigating to other sites.

HOW TO FIX Add `Referrer-Policy: strict-origin-when-cross-origin`.

Learn more →

HDR_PERMISSIONS_POLICY · v1.0.0 · PRIVACY

Permissions-Policy

WHAT IT CHECKS That browser features (camera, microphone, geolocation…) the site may use are restricted.

HOW TO FIX Add `Permissions-Policy` disabling what you do not use (e.g. `camera=(), microphone=(), geolocation=()`).

Learn more →

HDR_CLICKJACKING · v1.0.0 · SECURITY

Framing protection (clickjacking)

WHAT IT CHECKS That embedding the site in foreign frames is prevented (`X-Frame-Options` or CSP `frame-ancestors`).

HOW TO FIX Add `Content-Security-Policy: frame-ancestors 'self'` or `X-Frame-Options: SAMEORIGIN`.

Learn more →

HDR_VERSION_DISCLOSURE · v1.0.0 · SECURITY

Software version disclosure

WHAT IT CHECKS Whether the `Server` or `X-Powered-By` headers reveal software and version.

HOW TO FIX Hide the version (e.g. `server_tokens off` in nginx) and remove `X-Powered-By`.

LIMITATIONS Showing the version does not mean it is vulnerable: it only eases reconnaissance.

Learn more →

BROWSER ENGINE

A11Y_AUTOMATED · v1.0.0 · ACCESSIBILITY

Automated accessibility checks

WHAT IT CHECKS Overall result of automated accessibility tests (axe-core) on the page and a small sample of the same site.

HOW TO FIX Review each listed issue: usually alt text, contrast, form labels or heading structure.

LIMITATIONS Automated tests detect only part of accessibility issues. Full conformance (e.g. WCAG 2.1 AA) requires manual review.

Learn more →

A11Y_VIOLATION · v1.0.0 · ACCESSIBILITY

Accessibility issue

WHAT IT CHECKS An axe-core rule failing on one or more elements of the analysed pages.

HOW TO FIX Follow the guide linked in the evidence (helpUrl) and fix the listed elements.

LIMITATIONS Up to 3 elements per page are shown as examples; there may be more.

Learn more →

PRIV_COOKIES_INITIAL · v1.0.0 · PRIVACY

Cookies set before any interaction

WHAT IT CHECKS Which cookies (name and attributes only, never values) and local storage the site sets on load, before the visitor does anything.

HOW TO FIX Non-essential cookies (analytics, advertising) should not be set until the visitor accepts them.

LIMITATIONS The cookie banner is not interacted with (reject/accept scenarios arrive in Phase 4). Technical assessment, not legal advice.

Learn more →

PRIV_THIRD_PARTIES · v1.0.0 · PRIVACY

Third-party requests on load

WHAT IT CHECKS Which external domains the browser contacts when loading the page (grouped by registrable domain).

HOW TO FIX Check each third party is necessary and declared in your privacy policy.

LIMITATIONS A third party is not a problem in itself (CDN, fonts, payments…): it is information to review.

Learn more →

PRIV_TRACKERS_INITIAL · v1.0.0 · PRIVACY

Known trackers loaded before consent

WHAT IT CHECKS Whether known analytics or advertising domains are contacted before any visitor interaction.

HOW TO FIX Load analytics and advertising only after consent (your CMP should block them until then).

LIMITATIONS Detection based on an in-house list of well-known public domains: not every tracker is detected. Some tools may run in cookieless mode.

Learn more →

BROWSER_RENDER · v1.0.0 · HTTP

Page rendered in a real browser

WHAT IT CHECKS That the page can be loaded in a real browser (Chromium) for the accessibility and privacy checks.

HOW TO FIX If it fails, check whether the site blocks automated browsers or takes too long to load.