Calendly
Shareable booking links that check your connected calendars for availability, so people pick a meeting time without back-and-forth email.
Compare
Security headers: D, 40 out of 100
Number 59 of 95 in the ranking. Missing 5 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, calendly.com is more exposed to malicious JavaScript, redirected forms, hijacked payments and clickjacking.
Missing 5
-
Content-Security-Policy 0 of 25
Tells the browser which scripts may run on the page, where its forms may submit, and where it may send data.
Without it: This is the main defence against malicious JavaScript. If an attacker gets any script onto the page (through a bug, a compromised analytics tag, chat widget or ad, or a poisoned package), the browser runs it with the signed-in user's full access. It can capture what they type, quietly point a sign-in or checkout form at the attacker's server, and skim card numbers as they are entered. A strict policy blocks scripts it does not list, and its form-action and connect-src rules leave stolen data nowhere to go.
-
Frame protection 0 of 10
X-Frame-Options or the CSP frame-ancestors directive: decides which sites may show this one inside a frame.
Without it: Clickjacking. Another site loads the product invisibly in a frame and lines its real buttons up under something the user wants to click, so a signed-in user approves a payment, changes their account email or grants access without seeing it.
-
Referrer-Policy 0 of 10
Limits how much of the current URL is passed to other sites when a user follows a link or the page loads a third-party resource.
Without it: Full URLs, including paths and query strings that can carry document IDs, search terms, customer names or reset tokens, can leak to every outside script, image host and outbound link. Recent browsers default to a safer policy; older ones and embedded webviews do not.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 4
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Cross-Origin-Opener-Policy 5 of 5
same-origin
-
No version disclosure 5 of 5
server: cloudflare