Fairytale Genie
Personalized, AI-illustrated storybooks starring your child, as a PDF download or a printed book.
Compare
Security headers: A, 85 out of 100
Number 19 of 95 in the ranking. Missing 2 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, fairytalegenie.com is more exposed to clickjacking.
Missing 2
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
Sent 7
-
Content-Security-Policy 25 of 25
default-src 'self';script-src 'self' 'nonce-9GP0VvNh2iiiYeqMaDf2cA==' https://*.stripe.com https://*.posthog.com https://appleid.apple.com;style-src 'self' 'nonce-9GP0VvNh2iiiYeqMaDf2cA==' 'sha256-KmuybpeIODTiqckdvTvlqNTvo/FCXZzUUlV4T9gJkoo=' 'sha256-k0WLd3ulXPrpY7QZFCS+T0vX8ftqew4kV7Dl98xSR+o=' https://*.stripe.com https://appleid.apple.com 'unsafe-hashes' 'sha256-EOk2h4m/EyL2JzhtPSfU1+Cqtp0FxcVWkAS78EgDGWE=' 'sha256-lnvGaU4yI7XczGIrwkqtzd9e9mY5FqAgLKGSZ1l3Wfw=';img-src 'self' data: https://*.amazonaws.com https://*.cloudfront.net https://i.ytimg.com;connect-src 'self' https://*.amazonaws.com https://*.cloudfront.net https://formspree.io https://crm.devopser.io https://*.stripe.com https://*.posthog.com https://ipapi.co https://appleid.apple.com;font-src 'self' https://fonts.gstatic.com;object-src 'none';media-src 'self';frame-src 'self' https://*.stripe.com https://www.youtube.com https://youtube.com;worker-src 'self' blob:;script-src-attr 'none';base-uri 'self';form-action 'self';frame-ancestors 'self';upgrade-insecure-requests
-
Strict-Transport-Security 20 of 20
max-age=15552000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
DENY
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
Cross-Origin-Resource-Policy 5 of 5
cross-origin
-
No version disclosure 5 of 5