Loom
Records your screen and camera together and shares the video as a link, with viewer comments, emoji reactions, transcripts and basic trimming.
Compare
Security headers: D, 45 out of 100
Number 56 of 95 in the ranking. Missing 5 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, loom.com is more exposed to malicious JavaScript, redirected forms, hijacked payments and clickjacking.
Missing 5
-
Content-Security-Policy 0 of 25
Tells the browser which scripts may run on the page, where its forms may submit, and where it may send data.
Without it: This is the main defence against malicious JavaScript. If an attacker gets any script onto the page (through a bug, a compromised analytics tag, chat widget or ad, or a poisoned package), the browser runs it with the signed-in user's full access. It can capture what they type, quietly point a sign-in or checkout form at the attacker's server, and skim card numbers as they are entered. A strict policy blocks scripts it does not list, and its form-action and connect-src rules leave stolen data nowhere to go.
-
Frame protection 0 of 10
X-Frame-Options or the CSP frame-ancestors directive: decides which sites may show this one inside a frame.
Without it: Clickjacking. Another site loads the product invisibly in a frame and lines its real buttons up under something the user wants to click, so a signed-in user approves a payment, changes their account email or grants access without seeing it.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 4
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
No version disclosure 5 of 5
server: Vercel