{
 "host": "sentry-demo-mozmurray.pages.dev",
 "scan": {
  "id": 124615880,
  "details_url": "https://developer.mozilla.org/en-US/observatory/analyze?host=sentry-demo-mozmurray.pages.dev",
  "algorithm_version": 6,
  "scanned_at": "2026-09-30T18:42:30.519Z",
  "error": null,
  "grade": "A+",
  "score": 135,
  "status_code": 200,
  "tests_failed": 0,
  "tests_passed": 12,
  "tests_quantity": 12
 },
 "detail": {
  "history": [
   {
    "id": 124614299,
    "scanned_at": "2026-09-30T18:32:54.057Z",
    "grade": "C",
    "score": 55
   },
   {
    "id": 124615880,
    "scanned_at": "2026-09-30T18:42:30.519Z",
    "grade": "A+",
    "score": 135
   }
  ],
  "scan": {
   "id": 124615880,
   "algorithm_version": 6,
   "scanned_at": "2026-09-30T18:42:30.519Z",
   "error": null,
   "grade": "A+",
   "response_headers": {
    "nel": "{\"report_to\":\"cf-nel\",\"success_fraction\":0.0,\"max_age\":604800}",
    "date": "Wed, 30 Sep 2026 18:42:30 GMT",
    "etag": "W/\"9131122d256a1d4eb824d6a13159b3cc\"",
    "cf-ray": "a4355e2cfe0bc4cb-SEA",
    "server": "cloudflare",
    "alt-svc": "h3=\":443\"; ma=86400",
    "report-to": "{\"group\":\"cf-nel\",\"max_age\":604800,\"endpoints\":[{\"url\":\"https://a.nel.cloudflare.com/report/v4?s=da2P%2FA5atnjj3AFByMvSpDyh9KlB48rb%2FcIazpfDn%2BF8Q79iwmJnuf7p%2FMzrVzBB9ZO6UAoRtE84qXQf25OGR%2BOT%2BJqsLjYEeVLRIDxNmYCwLH8MWhOTxNIh9v6fxrmF0phAbNfRtdc%2FHnVyE2WD2UsR\"}]}",
    "connection": "close",
    "content-type": "text/html; charset=utf-8",
    "cache-control": "public, max-age=0, must-revalidate",
    "referrer-policy": "strict-origin-when-cross-origin",
    "x-frame-options": "DENY",
    "transfer-encoding": "chunked",
    "permissions-policy": "camera=(), microphone=(), geolocation=(), payment=(), usb=()",
    "x-content-type-options": "nosniff",
    "content-security-policy": "default-src 'self'; script-src 'self' 'sha256-LQf/PklFFHtRAIEhN87kJhqAQ98H3aQNLqFahbPX51w='; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests",
    "cross-origin-opener-policy": "same-origin",
    "access-control-allow-origin": "*",
    "cross-origin-resource-policy": "same-origin"
   },
   "score": 135,
   "status_code": 200,
   "tests_failed": 0,
   "tests_passed": 12,
   "tests_quantity": 12
  },
  "tests": {
   "content-security-policy": {
    "expectation": "csp-implemented-with-no-unsafe",
    "name": "content-security-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CSP",
    "title": "Content Security Policy (CSP)",
    "pass": true,
    "result": "csp-implemented-with-unsafe-inline-in-style-src-only",
    "score_description": "<p>\n      Content Security Policy (CSP) implemented with unsafe sources inside style-src. This includes <code>'unsafe-inline'</code>, <code>data:</code> or overly broad sources such as <code>https</code>. <code>'form-action'</code> is set to <code>'self'</code>, <code>'none'</code> or <code>'specific source'</code>\n      </p>",
    "recommendation": "\n        <p>\n          Lock down <code>style-src</code> directive, removing <code>'unsafe-inline'</code>, <code>data:</code> and broad sources.\n        </p>",
    "score_modifier": 0,
    "data": {
     "img-src": [
      "'self'",
      "data:"
     ],
     "base-uri": [
      "'self'"
     ],
     "font-src": [
      "'self'"
     ],
     "frame-src": [
      "'none'"
     ],
     "style-src": [
      "'self'",
      "'unsafe-inline'"
     ],
     "object-src": [
      "'none'"
     ],
     "script-src": [
      "'self'",
      "'sha256-lqf/pklffhtraiehn87kjhqaq98h3aqnlqfahbpx51w='"
     ],
     "connect-src": [
      "'self'"
     ],
     "default-src": [
      "'self'"
     ],
     "form-action": [
      "'self'"
     ],
     "frame-ancestors": [
      "'none'"
     ],
     "upgrade-insecure-requests": [
      "'none'"
     ]
    },
    "http": true,
    "meta": false,
    "policy": {
     "antiClickjacking": {
      "pass": true,
      "description": "<p>Clickjacking protection, using <code>frame-ancestors</code></p>",
      "info": "<p>The use of CSP's <code>frame-ancestors</code> directive offers fine-grained control over who can frame your site.</p>"
     },
     "defaultNone": {
      "pass": false,
      "description": "<p>Deny by default, using <code>default-src 'none'</code></p>",
      "info": "<p>Denying by default using <code>default-src 'none'</code>can ensure that your Content Security Policy doesn't allow the loading of resources you didn't intend to allow.</p>"
     },
     "insecureBaseUri": {
      "pass": false,
      "description": "<p>Restricts use of the <code>&lt;base&gt;</code> tag by using <code>base-uri 'none'</code>, <code>base-uri 'self'</code>, or specific origins.</p>",
      "info": "<p>The <code>&lt;base&gt;</code> tag can be used to trick your site into loading scripts from untrusted origins.</p>"
     },
     "insecureFormAction": {
      "pass": false,
      "description": "<p>Restricts where <code>&lt;form&gt;</code> contents may be submitted by using <code>form-action 'none'</code>, <code>form-action 'self'</code>, or specific URIs</p>",
      "info": "<p>Malicious JavaScript or content injection could modify where sensitive form data is submitted to or create additional forms for data exfiltration.</p>"
     },
     "insecureSchemeActive": {
      "pass": false,
      "description": "<p>Blocks loading of active content over HTTP or FTP</p>",
      "info": "<p>Loading JavaScript or plugins can allow a man-in-the-middle to execute arbitrary code or your website. Restricting your policy and changing links to HTTPS can help prevent this.</p>"
     },
     "insecureSchemePassive": {
      "pass": false,
      "description": "<p>Blocks loading of passive content over HTTP or FTP</p>",
      "info": "<p>This site's Content Security Policy allows the loading of passive content such as images or videos over insecure protocols such as HTTP or FTP. Consider changing them to load them over HTTPS.</p>"
     },
     "strictDynamic": {
      "pass": null,
      "description": "<p>Uses CSP3's <code>'strict-dynamic'</code> directive to allow dynamic script loading (optional)</p>",
      "info": "<p><code>'strict-dynamic'</code> lets you use a JavaScript shim loader to load all your site's JavaScript dynamically, without having to track <code>script-src</code> origins.</p>"
     },
     "unsafeEval": {
      "pass": false,
      "description": "<p>Blocks execution of JavaScript's <code>eval()</code> function by not allowing <code>'unsafe-eval'</code> inside <code>script-src</code></p>",
      "info": "<p>Blocking the use of JavaScript's <code>eval()</code> function can help prevent the execution of untrusted code.</p>"
     },
     "unsafeInline": {
      "pass": false,
      "description": "<p>Blocks execution of inline JavaScript by not allowing <code>'unsafe-inline'</code> inside <code>script-src</code></p>",
      "info": "<p>Blocking the execution of inline JavaScript provides CSP's strongest protection against cross-site scripting attacks. Moving JavaScript to external files can also help make your site more maintainable.</p>"
     },
     "unsafeInlineStyle": {
      "pass": true,
      "description": "<p>Blocks inline styles by not allowing <code>'unsafe-inline'</code> inside <code>style-src</code></p>",
      "info": "<p>Blocking inline styles can help prevent attackers from modifying the contents or appearance of your page. Moving styles to external stylesheets can also help make your site more maintainable.</p>"
     },
     "unsafeObjects": {
      "pass": false,
      "description": "<p>Blocks execution of plug-ins, using <code>object-src</code> restrictions</p>",
      "info": "<p>Blocking the execution of plug-ins via <code>object-src 'none'</code> or as inherited from <code>default-src</code> can prevent attackers from loading Flash or Java in the context of your page.</p>"
     }
    },
    "num_policies": 1
   },
   "cookies": {
    "expectation": "cookies-secure-with-httponly-sessions",
    "name": "cookies",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/Cookies",
    "title": "Cookies",
    "pass": null,
    "result": "cookies-not-found",
    "score_description": "<p>\n      No cookies detected\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": null,
    "same_site": false
   },
   "cross-origin-embedder-policy": {
    "expectation": "coep-not-implemented",
    "name": "cross-origin-embedder-policy",
    "link": "/en-US/docs/Web/HTTP/Reference/Headers/Cross-Origin-Embedder-Policy",
    "title": "Cross Origin Embedder Policy",
    "pass": true,
    "result": "coep-not-implemented",
    "score_description": "<p>\n      <code>Cross-Origin-Embedder-Policy</code> header not implemented.\n      </p>",
    "recommendation": "<p>\n      Set to <code>require-corp</code> or <code>credentialless</code>.\n      </p>",
    "score_modifier": 0,
    "data": null,
    "http": false
   },
   "cross-origin-opener-policy": {
    "expectation": "coop-not-implemented",
    "name": "cross-origin-opener-policy",
    "link": "/en-US/docs/Web/HTTP/Reference/Headers/Cross-Origin-Opener-Policy",
    "title": "Cross Origin Opener Policy",
    "pass": true,
    "result": "coop-implemented-with-same-origin",
    "score_description": "<p>\n      <code>Cross-Origin-Opener-Policy</code> header set to <code>same-origin</code>, enforcing site isolation from the opener.\n      </p>",
    "recommendation": "",
    "score_modifier": 10,
    "data": "same-origin",
    "http": true
   },
   "cross-origin-resource-sharing": {
    "expectation": "cross-origin-resource-sharing-not-implemented",
    "name": "cross-origin-resource-sharing",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CORS",
    "title": "Cross Origin Resource Sharing (CORS)",
    "pass": true,
    "result": "cross-origin-resource-sharing-not-implemented",
    "score_description": "<p>\n      Content is not visible via cross-origin resource sharing (CORS) files or headers.\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": null
   },
   "redirection": {
    "expectation": "redirection-to-https",
    "name": "redirection",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/TLS#http_redirection",
    "title": "Redirection",
    "pass": true,
    "result": "redirection-all-redirects-preloaded",
    "score_description": "<p>\n      All hosts redirected to are in the HTTP Strict Transport Security (HSTS) preload list.\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "route": [
     "http://sentry-demo-mozmurray.pages.dev/",
     "https://sentry-demo-mozmurray.pages.dev/"
    ],
    "redirects": true,
    "status_code": 200,
    "destination": "https://sentry-demo-mozmurray.pages.dev/"
   },
   "referrer-policy": {
    "expectation": "referrer-policy-private",
    "name": "referrer-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/Referrer_policy",
    "title": "Referrer Policy",
    "pass": true,
    "result": "referrer-policy-private",
    "score_description": "<p>\n        <code>Referrer-Policy</code> header set to <code>no-referrer</code>, <code>same-origin</code>, <code>strict-origin</code> or <code>strict-origin-when-cross-origin</code>.\n        </p>",
    "recommendation": "<p class=\"obs-none\">None<p>",
    "score_modifier": 5,
    "data": "strict-origin-when-cross-origin",
    "http": true,
    "meta": false
   },
   "strict-transport-security": {
    "expectation": "hsts-implemented-max-age-at-least-six-months",
    "name": "strict-transport-security",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/TLS#http_strict_transport_security_implementation",
    "title": "Strict Transport Security (HSTS)",
    "pass": true,
    "result": "hsts-preloaded",
    "score_description": "<p>\n        Preloaded via the HTTP Strict Transport Security (HSTS) preloading process.\n        </p>",
    "recommendation": "",
    "score_modifier": 5,
    "data": null,
    "max_age": null,
    "preload": false,
    "preloaded": true,
    "include_sub_domains": true
   },
   "subresource-integrity": {
    "expectation": "sri-implemented-and-external-scripts-loaded-securely",
    "name": "subresource-integrity",
    "link": "/en-US/docs/Web/Security/Subresource_Integrity",
    "title": "Subresource Integrity",
    "pass": null,
    "result": "sri-not-implemented-but-all-scripts-loaded-from-secure-origin",
    "score_description": "<p>\n      Subresource Integrity (SRI) not implemented, but all scripts are loaded from a similar origin.\n      </p>",
    "recommendation": "<p>\n      Add SRI for bonus points.\n      </p>",
    "score_modifier": 0,
    "data": {}
   },
   "x-content-type-options": {
    "expectation": "x-content-type-options-nosniff",
    "name": "x-content-type-options",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/MIME_types",
    "title": "X-Content-Type-Options",
    "pass": true,
    "result": "x-content-type-options-nosniff",
    "score_description": "<p>\n      <code>X-Content-Type-Options</code> header set to <code>nosniff</code>.\n      </p>",
    "recommendation": "",
    "score_modifier": 0,
    "data": "nosniff"
   },
   "x-frame-options": {
    "expectation": "x-frame-options-sameorigin-or-deny",
    "name": "x-frame-options",
    "link": "/en-US/docs/Web/Security/Attacks/Clickjacking",
    "title": "X-Frame-Options",
    "pass": true,
    "result": "x-frame-options-implemented-via-csp",
    "score_description": "<p>\n      <code>X-Frame-Options</code> (XFO) implemented via the CSP frame-ancestors directive.\n      </p>",
    "recommendation": "",
    "score_modifier": 5,
    "data": "DENY"
   },
   "cross-origin-resource-policy": {
    "expectation": "corp-implemented-with-same-site",
    "name": "cross-origin-resource-policy",
    "link": "/en-US/docs/Web/Security/Practical_implementation_guides/CORP",
    "title": "Cross Origin Resource Policy",
    "pass": true,
    "result": "corp-implemented-with-same-origin",
    "score_description": "<p>\n      Cross Origin Resource Policy (CORP) implemented, prevents leaks into cross-origin contexts.\n      </p>",
    "recommendation": "",
    "score_modifier": 10,
    "data": "same-origin",
    "http": true,
    "meta": false
   }
  }
 }
}