Asana
Work management app for tracking team tasks and projects in list, board, timeline and calendar views, with assignees, due dates and rule-based automations.
Compare
Security headers: C, 65 out of 100
Number 43 of 95 in the ranking. Missing 5 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, asana.com is more exposed to clickjacking.
Missing 5
-
Referrer-Policy 0 of 10
Limits how much of the current URL is passed to other sites when a user follows a link or the page loads a third-party resource.
Without it: Full URLs, including paths and query strings that can carry document IDs, search terms, customer names or reset tokens, can leak to every outside script, image host and outbound link. Recent browsers default to a safer policy; older ones and embedded webviews do not.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
-
No version disclosure 0 of 5
Keeps the Server and X-Powered-By headers from announcing exact software versions.
Without it: A header like "nginx/1.18.0" or "PHP/7.4" tells an attacker which known vulnerabilities to try, and flags possibly unpatched software to every automated scanner on the internet.
Sent 4
-
Content-Security-Policy 25 of 25
worker-src blob:; frame-ancestors 'self' https://www.surveymonkey.com https://google.com https://app.asana.com https://prod-eu1.app.asana.com https://prod-au1.app.asana.com https://prod-jp1.app.asana.com https://blog.asana.com https://academy.asana.com https://app.optimizely.com/ https://app.contentful.com; report-uri https://app.asana.com/-/csp_report; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://app.spara.co https://*.spara.co https://*.vector.co https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://ajax.aspnetcdn.com https://bat.bing.com https://sjs.bizographics.com https://ct.capterra.com https://googleads.g.doubleclick.net https://connect.facebook.net https://tracking.g2crowd.com https://www.google-analytics.com https://apis.google.com https://www.googleadservices.com https://*.googleapis.com https://tpc.googlesyndication.com https://www.googletagmanager.com https://ssl.gstatic.com https://cdn.jotfor.ms https://form.jotform.us https://snap.licdn.com https://px.ads.linkedin.com https://www.linkedin.com https://luna1.co https://js.recurly.com https://fast.wistia.com https://fast.wistia.net https://www.youtube.com https://s.ytimg.com https://*.marketo.com https://*.marketo.net https://cdnjs.cloudflare.com https://api.ipify.org https://cdn.pdst.fm https://*.vimeocdn.com https://resources.asana.com https://w58858w0sjxx.statuspage.io https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.logs.datadoghq.com https://www.datadoghq-browser-agent.com https://tagmanager.google.com/debug https://t.contentsquare.net contentsquare.com app.contentsquare.com https://cdn.jsdelivr.net/npm/@sheerid/jslib@1/ https://v2.listenloop.com https://boards.greenhouse.io/embed/job_board/js https://job-boards.greenhouse.io https://www.redditstatic.com/ads/pixel.js https://yjtag.jp/tag.js https://s.yjtag.jp/tag.js https://s.yimg.jp/ https://yjtag.yahoo.co.jp/tag https://analytics.tiktok.com/i18n/pixel/ https://s.pinimg.com/ct/ https://b92.yahoo.co.jp/rt/ https://t-antenna.asana.com/ https://scripts.postie.com/wbgboxjj/lp.1.js https://b91.yahoo.co.jp/pagead/ https://b98.yahoo.co.jp/ https://accounts.google.com/gsi/client https://js.adstk.io/convpixel.js https://a.quora.com/qevents.js https://d34r8q7sht0t9k.cloudfront.net/tag.js https://collector-39548.us.tvsquared.com/tv2track.js https://*.qualified.com https://static.xingcdn.com/xingtrk/index.js https://ct.pinterest.com/static/ct/token_create.js https://*.6sc.co https://*.6sense.com https://js.zi-scripts.com/ https://*.mountain.com/ https://c0.adalyser.com/adalyser.js https://dyv6f9ner1ir9.cloudfront.net/assets/js/nloader.js https://pagead2.googlesyndication.com https://c.amazon-adsystem.com/aat/amzn.js https://*.optimizely.com https://optimizely.s3.amazonaws.com https://tr.capterra.com https://pixel.byspotify.com/ping.min.js https://bzrcdn.openai.com/sdk/oaiq.min.js https://capi-automation.s3.us-east-2.amazonaws.com/public/client_js/capiParamBuilder/clientParamBuilder.bundle.js https://cdp-cdn.asana.com https://tag.sites-analytics.com https://log.sites-analytics.com
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
DENY