Notion
Docs, wikis and databases in one workspace, built from nestable pages and blocks, with real-time collaboration and templates.
Compare
Security headers: C, 65 out of 100
Number 46 of 95 in the ranking. Missing 5 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, notion.com is more exposed to malicious JavaScript and clickjacking.
Missing 5
-
X-Content-Type-Options 0 of 10
Stops the browser guessing a file's type instead of trusting the type the server declared.
Without it: A file uploaded as an image or plain text can be reinterpreted as HTML or script and run inside the product's own origin: malicious JavaScript delivered through a harmless-looking upload feature.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
-
No version disclosure 0 of 5
Keeps the Server and X-Powered-By headers from announcing exact software versions.
Without it: A header like "nginx/1.18.0" or "PHP/7.4" tells an attacker which known vulnerabilities to try, and flags possibly unpatched software to every automated scanner on the internet.
Sent 4
-
Content-Security-Policy 25 of 25
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://gist.github.com https://apis.google.com https://cdn.amplitude.com https://api.amplitude.com https://dev-embed.notion.co https://embed.notion.co https://static.zdassets.com https://api.smooch.io https://solve-widget.forethought.ai https://decagon.ai https://http-inputs-notion.splunkcloud.com https://*.sentry.io https://checkout.stripe.com https://js.stripe.com https://embed.typeform.com https://admin.typeform.com https://ucv.bynder.com https://js.sentry-cdn.com https://js.chilipiper.com https://platform.twitter.com https://cdn.syndication.twimg.com https://accounts.google.com https://vimeo.com https://player.vimeo.com https://youtube.com https://www.youtube.com https://app.cal.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://cdn.metadata.io https://platformapi.metadata.io https://api-gw.metadata.io https://cdn.cr-relay.com https://d2hrivdxn8ekm8.cloudfront.net https://d1lu3pmaz2ilpx.cloudfront.net https://dvqigh9b7wa32.cloudfront.net https://d330aiyvva2oww.cloudfront.net https://d34r8q7sht0t9k.cloudfront.net https://transcend-cdn.com https://wcs.naver.com https://wcs.naver.net https://ssl.pstatic.net https://cdn01.boxcdn.net https://api.tailorhq.ai https://app.tailorhq.ai https://cdn.tailorhq.ai https://cached-api.tailorhq.ai https://cdn.sprig.com https://assets.customer.io https://track.customer.io https://code.gist.build https://www.google.com https://www.gstatic.com https://challenges.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://x.clearbitjs.com https://connect.facebook.net https://snap.licdn.com/ https://px.ads.linkedin.com/ https://munchkin.marketo.net https://info.notion.com https://bat.bing.com https://s.yimg.jp https://www.youtube-nocookie.com https://www.youtube.com/iframe_api https://js.partnerstack.com https://partnerlinks.io https://analytics.tiktok.com/ https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live https://www.redditstatic.com https://static.ads-twitter.com https://insights.metadata.io https://bzrcdn.openai.com https://acdn.adnxs.com/dmp/up/pixie.js https://dx.mountain.com https://a.usbrowserspeed.com https://static.hotjar.com https://script.hotjar.com https://cloud.memsource.com https://editor.memsource.com https://*.vector.co https://d-code.liadm.com/ https://*.usbrowserspeed.com;connect-src 'self' data: blob: https://img.notionusercontent.com https://artifact.notionusercontent.com https://notion.so/eap https://cdn.amplitude.com https://api.amplitude.com https://app.notion.com notion://app.notion.com https://app.prod.notion.com https://app.canary.notion.com https://api.embed.ly https://dev-embed.notion.co https://embed.notion.co https://ekr.zdassets.com https://ekr.zendesk.com https://makenotion.zendesk.com https://api.smooch.io wss://api.smooch.io https://api.forethought.ai https://http-inputs-notion.splunkcloud.com https://*.sentry.io https://checkout.stripe.com https://js.stripe.com https://m.stripe.com https://library.notion.com https://d8ejoa1fys2rk.cloudfront.net https://cdn.contentful.com https://preview.contentful.com https://images.ctfassets.net https://tracking.chilipiper.com https://api.chilipiper.com https://api.unsplash.com https://api.giphy.com/ https://giphy-analytics.giphy.com/ https://media0.giphy.com/ https://media1.giphy.com/ https://media2.giphy.com/ https://media3.giphy.com/ https://media4.giphy.com/ https://media5.giphy.com/ https://media6.giphy.com/ https://media7.giphy.com/ https://media8.giphy.com/ https://media9.giphy.com/ https://media10.giphy.com/ https://boards-api.greenhouse.io https://accounts.google.com https://oauth2.googleapis.com https://vimeo.com https://player.vimeo.com https://youtube.com https://www.youtube.com https://www.googletagmanager.com https://analytics.google.com https://ad.doubleclick.net/ccm/s/collect https://www.googleadservices.com https://googleads.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://www.google-analytics.com https://cdn.metadata.io https://platformapi.metadata.io https://api-gw.metadata.io https://api.cr-relay.com https://d2hrivdxn8ekm8.cloudfront.net https://d1lu3pmaz2ilpx.cloudfront.net https://dvqigh9b7wa32.cloudfront.net https://d330aiyvva2oww.cloudfront.net https://verifi.podscribe.com https://verifi.pdscrb.com https://pixel.tapad.com https://ipv4.podscribe.com https://ipv4.pdscrb.com https://transcend-cdn.com https://telemetry.transcend.io https://wcs.naver.com https://api.statsig.com https://statsigapi.net https://exp.notion.com https://us1.gb-ingest.com https://api.box.com https://api.tailorhq.ai https://app.tailorhq.ai https://cdn.tailorhq.ai https://cached-api.tailorhq.ai https://*.mux.com https://api.sprig.com https://storage.googleapis.com https://cdn.sprig.com https://cdn.userleap.com https://assets.customer.io https://track.customer.io https://*.api.gist.build https://*.cloud.gist.build https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://tiles.versatiles.org https://maps.googleapis.com https://places.googleapis.com https://8d4f9jvuda.algolia.net https://pagead2.googlesyndication.com https://google.com https://x.clearbitjs.com https://app.clearbitjs.com https://connect.facebook.net https://snap.licdn.com/ https://px.ads.linkedin.com/ https://munchkin.marketo.net https://*.mktoresp.com https://info.notion.com https://bat.bing.com https://s.yimg.jp https://www.youtube-nocookie.com https://www.youtube.com/iframe_api https://js.partnerstack.com https://grsm.io https://partnerlinks.io https://analytics.tiktok.com/ https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live https://www.redditstatic.com https://static.ads-twitter.com https://insights.metadata.io https://bzr.openai.com https://acdn.adnxs.com/dmp/up/pixie.js https://dx.mountain.com https://a.usbrowserspeed.com https://api.mail.dev.notion.so/graphql https://api.mail.notion.so/graphql https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://cloud.memsource.com https://editor.memsource.com https://api.vector.co/;font-src 'self' data: https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://d8ejoa1fys2rk.cloudfront.net https://cdn01.boxcdn.net https://fonts.gstatic.com;img-src 'self' data: blob: https: https://img.notionusercontent.com https://mail-resource-proxy.mail.notion.com https://app.notion.com notion://app.notion.com https://app.prod.notion.com https://app.canary.notion.com https://images.ctfassets.net https://platform.twitter.com https://syndication.twitter.com https://pbs.twimg.com https://ton.twimg.com https://region1.google-analytics.com https://region1.analytics.google.com https://*.mux.com https://track.customer.io https://bzr.openai.com;style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://github.githubassets.com https://d8ejoa1fys2rk.cloudfront.net https://js.chilipiper.com https://platform.twitter.com https://ton.twimg.com https://accounts.google.com https://transcend-cdn.com https://cdn01.boxcdn.net https://code.gist.build https://hcaptcha.com https://*.hcaptcha.com https://fonts.googleapis.com;frame-src 'self' https: http: https://artifact.notionusercontent.com https://app.notion.com notion://app.notion.com https://app.prod.notion.com https://app.canary.notion.com https://accounts.google.com https://renderer.gist.build https://code.gist.build https://challenges.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com https://notion.notion.site https://notion-templates.notion.site;frame-ancestors 'self' https://app.notion.com notion://app.notion.com https://app.prod.notion.com https://app.canary.notion.com notion://www.notion.so https://app.contentful.com;worker-src 'self' blob:;child-src 'self' blob:;media-src blob: https: http: https://*.mux.com
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
Frame protection 10 of 10
CSP frame-ancestors
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin