Dropbox
Cloud file storage that syncs across desktop, mobile and web, with shared folders, version history and shareable links.
Compare
Security headers: A, 85 out of 100
Number 18 of 95 in the ranking. Missing 2 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
Missing 2
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 7
-
Content-Security-Policy 25 of 25
base-uri 'self'; child-src https://www.dropbox.com/static/serviceworker/ blob:; connect-src https://* ws://127.0.0.1:*/ws blob: wss://dsimports.dropbox.com/; default-src 'none'; font-src 'self' data: https://*; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker https://*.sharepoint.com/; frame-ancestors 'self'; frame-src https://* dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss: blob:; img-src https://* data: blob:; media-src https://* blob:; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://edge-live.dropboxstatic.com/static/; report-to csp-metaserver-whitelist; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist; script-src 'unsafe-eval' 'inline-speculation-rules' https://www.dropbox.com/static/api/ https://www.dropbox.com/pithos/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://edge-live.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://reveal.clearbit.com/v1/companies/reveal https://www.paypal.com/sdk/js https://applepay.cdn-apple.com https://snippet.meticulous.ai/record/ https://edge.cofra.me/cf-static-97646a4fe3e6.js https://edge.cofra.me/cf-static-4d85f2a0ba2d.js 'nonce-pMQ7eM4f9MVnzCUlaSzv4LYmUy4='; style-src https://* 'unsafe-inline' 'unsafe-eval'; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js https://www.dropbox.com/service_worker.js blob:, report-to csp-metaserver-dynamic; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-pMQ7eM4f9MVnzCUlaSzv4LYmUy4=' 'nonce-cRC7Dx66QroPZO6Ac4Y0AIuRab4='
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
Cross-Origin-Opener-Policy 5 of 5
same-origin-allow-popups
-
No version disclosure 5 of 5
server: envoy