SafeNet Creations
Tamil + English AI voice agents, WhatsApp automation, and bilingual websites for GTA businesses — CAD quotes, written scope before payment.
Compare
Security headers: A, 90 out of 100
Number 15 of 95 in the ranking. Missing 1 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, safenetcreations.com is more exposed to hijacked payments and clickjacking.
Missing 1
-
Frame protection 0 of 10
X-Frame-Options or the CSP frame-ancestors directive: decides which sites may show this one inside a frame.
Without it: Clickjacking. Another site loads the product invisibly in a frame and lines its real buttons up under something the user wants to click, so a signed-in user approves a payment, changes their account email or grants access without seeing it.
Sent 8
-
Content-Security-Policy 25 of 25
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://apis.google.com https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https: blob: https://s.wordpress.com https://*.wordpress.com; connect-src 'self' https://www.google.com/measurement/ https://stats.g.doubleclick.net https://*.google-analytics.com https://www.google-analytics.com https://analytics.google.com https://api.emailjs.com https://firestore.googleapis.com https://identitytoolkit.googleapis.com https://securetoken.googleapis.com https://us-central1-safenet-creations-hub.cloudfunctions.net https://generativelanguage.googleapis.com wss://generativelanguage.googleapis.com https://api.elevenlabs.io wss://api.elevenlabs.io https://api.us.elevenlabs.io wss://api.us.elevenlabs.io https://www.bing.com https://translate.googleapis.com https://api.mymemory.translated.net https://www.googleapis.com https://recaptchaenterprise.googleapis.com https://firebaseappcheck.googleapis.com https://content-firebaseappcheck.googleapis.com https://www.google.com/recaptcha/; worker-src 'self' blob: https://cdnjs.cloudflare.com; frame-src 'self' https: http: data: blob: https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content;
-
Strict-Transport-Security 20 of 20
max-age=63072000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
Permissions-Policy 10 of 10
camera=(), microphone=(self), geolocation=(), payment=(), usb=(), vr=(), interest-cohort=(), accelerometer=(), gyroscope=(), magnetometer=()
-
Cross-Origin-Opener-Policy 5 of 5
same-origin-allow-popups
-
Cross-Origin-Resource-Policy 5 of 5
same-origin
-
No version disclosure 5 of 5