Slack
Team messaging organized into channels and threads, with search and thousands of app integrations.
Compare
Security headers: D, 50 out of 100
Number 54 of 95 in the ranking. Missing 4 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, slack.com is more exposed to malicious JavaScript, redirected forms and hijacked payments.
Missing 4
-
Content-Security-Policy 0 of 25
Tells the browser which scripts may run on the page, where its forms may submit, and where it may send data.
Without it: This is the main defence against malicious JavaScript. If an attacker gets any script onto the page (through a bug, a compromised analytics tag, chat widget or ad, or a poisoned package), the browser runs it with the signed-in user's full access. It can capture what they type, quietly point a sign-in or checkout form at the attacker's server, and skim card numbers as they are entered. A strict policy blocks scripts it does not list, and its form-action and connect-src rules leave stolen data nowhere to go.
-
X-Content-Type-Options 0 of 10
Stops the browser guessing a file's type instead of trusting the type the server declared.
Without it: A file uploaded as an image or plain text can be reinterpreted as HTML or script and run inside the product's own origin: malicious JavaScript delivered through a harmless-looking upload feature.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 5
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
no-referrer
-
Cross-Origin-Opener-Policy 5 of 5
same-origin-allow-popups
-
No version disclosure 5 of 5
server: Apache