Canva
Browser-based drag-and-drop editor for social graphics, presentations and print designs, with a large template library and real-time collaboration.
Compare
Security headers: B, 75 out of 100
Number 35 of 95 in the ranking. Missing 1 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, canva.com is more exposed to malicious JavaScript, redirected forms and hijacked payments.
Missing 1
-
Content-Security-Policy 0 of 25
Tells the browser which scripts may run on the page, where its forms may submit, and where it may send data.
Without it: This is the main defence against malicious JavaScript. If an attacker gets any script onto the page (through a bug, a compromised analytics tag, chat widget or ad, or a poisoned package), the browser runs it with the signed-in user's full access. It can capture what they type, quietly point a sign-in or checkout form at the attacker's server, and skim card numbers as they are entered. A strict policy blocks scripts it does not list, and its form-action and connect-src rules leave stolen data nowhere to go.
Sent 8
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
same-origin
-
Permissions-Policy 10 of 10
accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
-
Cross-Origin-Opener-Policy 5 of 5
same-origin
-
Cross-Origin-Resource-Policy 5 of 5
same-origin
-
No version disclosure 5 of 5
server: cloudflare