https://gsu.edu
Scan complete
gsu.edu
10 issues detected
Scanned 4 months ago
10
Total
0
Critical
0
High
2
Medium
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: Permissions-Policy -- Controls browser feature access
4 of 6 security headers configured
SSL certificate valid (391 days remaining) — issued by Internet2
HTTP correctly redirects to HTTPS
Cookies missing security flags (SameSite): __cf_bm
How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");
REST API user enumeration blocked
No external scripts detected
Checked against 11 blacklist services
Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.
Run Deep Scan — $1