ScanLabsAI

api.config-security.com security report

External security assessment · 8 issues detected.

ScanLabsAI ran a standard security scan of api.config-security.com, checking its SSL/TLS configuration, HTTP security headers, DNS records. The results below reflect what is detectable from outside the site and earned it an overall grade of B. api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks.

B
71/100
Security grade
Based on externally detectable SSL/TLS, security-header, DNS and vulnerability checks.
Critical 0
High 0
Medium 7
Low 1
Informational 0
Issues detected
  • Missing HTTP Strict Transport Security
    HTTP Strict Transport Security (HSTS) forces browsers to use HTTPS, preventing protocol-downgrade and man-in-the-middle attacks against users who type the bare domain.
  • Missing X-Frame-Options
    Without X-Frame-Options (or a CSP frame-ancestors rule) the site can be embedded in a hidden iframe and used for clickjacking attacks.
  • Server Software Disclosure
    This issue was detected during an external security scan and can weaken the site’s resistance to common web attacks. Run a full scan to see its severity, evidence and remediation steps.
  • Missing Referrer-Policy
    A Referrer-Policy header controls how much URL information leaks to third-party sites, protecting user privacy and internal paths.
  • Missing Permissions-Policy
    A Permissions-Policy header restricts which powerful browser features (camera, microphone, geolocation) pages and embedded content may use.
  • Missing Cross-Origin-Opener-Policy
    Cross-Origin-Opener-Policy isolates the browsing context, mitigating cross-window attacks and side-channel leaks such as Spectre.
  • Missing Cross-Origin-Resource-Policy
    Cross-Origin-Resource-Policy limits which origins can load your resources, reducing the risk of cross-origin data leaks.
  • Missing Cross-Origin-Embedder-Policy
    Cross-Origin-Embedder-Policy ensures resources are explicitly allowed to be embedded — a prerequisite for strong cross-origin isolation.

Run a full scan to see each finding's exact severity, evidence and step-by-step fix.

How api.config-security.com can improve its security

Get the full report + step-by-step fixes
See every finding in detail with AI-generated remediation for api.config-security.com.
View the full report →

Frequently asked questions

Is api.config-security.com safe?

Based on an external ScanLabsAI security scan, api.config-security.com scored B (71/100). api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks. An external scan measures publicly detectable security posture, not internal controls.

What does a B security grade mean?

The B grade reflects the SSL/TLS, security-header, DNS and known-vulnerability checks ScanLabsAI observed from outside api.config-security.com. api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks.

How is the api.config-security.com security score calculated?

ScanLabsAI weights findings by severity: critical and high-severity issues reduce the score the most, while common medium and low issues (such as missing security headers) have a smaller impact. The result is a 0–100 score mapped to a letter grade from A+ to F.

How can api.config-security.com improve its security score?

Address the 8 detected issues — starting with the highest severity — then re-scan to confirm. Common quick wins include adding missing security headers and enforcing HTTPS with HSTS.

How this report is produced

ScanLabsAI is an AI-powered website security scanner. This report is generated by a passive external scan — it reads publicly available information the way a visitor would and never attempts to exploit, alter or damage the site. Findings are weighted by severity to produce the 0–100 score and A+–F grade shown above. A grade reflects externally detectable posture and is not a guarantee of overall security.

ScanLabsAI runs a multi-engine security scan (SSL/TLS, security headers, DNS, and known-vulnerability checks) and grades a website's public security posture. Grades reflect issues detectable from the outside and are not a guarantee of overall security.

Scan your own site free → · Security Intel Hub · Claude / MCP