ScanLabsAI
api.config-security.com security report
External security assessment · 8 issues detected.
ScanLabsAI ran a standard security scan of api.config-security.com, checking its SSL/TLS configuration, HTTP security headers, DNS records. The results below reflect what is detectable from outside the site and earned it an overall grade of B. api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks.
Security grade
Based on externally detectable SSL/TLS, security-header, DNS and vulnerability checks.
Critical
0
High
0
Medium
7
Low
1
Informational
0
Issues detected
-
Missing HTTP Strict Transport Security
HTTP Strict Transport Security (HSTS) forces browsers to use HTTPS, preventing protocol-downgrade and man-in-the-middle attacks against users who type the bare domain.
-
Missing X-Frame-Options
Without X-Frame-Options (or a CSP frame-ancestors rule) the site can be embedded in a hidden iframe and used for clickjacking attacks.
-
Server Software Disclosure
This issue was detected during an external security scan and can weaken the site’s resistance to common web attacks. Run a full scan to see its severity, evidence and remediation steps.
-
Missing Referrer-Policy
A Referrer-Policy header controls how much URL information leaks to third-party sites, protecting user privacy and internal paths.
-
Missing Permissions-Policy
A Permissions-Policy header restricts which powerful browser features (camera, microphone, geolocation) pages and embedded content may use.
-
Missing Cross-Origin-Opener-Policy
Cross-Origin-Opener-Policy isolates the browsing context, mitigating cross-window attacks and side-channel leaks such as Spectre.
-
Missing Cross-Origin-Resource-Policy
Cross-Origin-Resource-Policy limits which origins can load your resources, reducing the risk of cross-origin data leaks.
-
Missing Cross-Origin-Embedder-Policy
Cross-Origin-Embedder-Policy ensures resources are explicitly allowed to be embedded — a prerequisite for strong cross-origin isolation.
Run a full scan to see each finding's exact severity, evidence and step-by-step fix.
How api.config-security.com can improve its security
- Fix the highest-severity findings first — critical and high issues carry the most risk.
- Add any missing HTTP security headers (CSP, HSTS, X-Frame-Options and friends) — these are common, quick wins.
- Enforce HTTPS everywhere and keep TLS certificates and software up to date.
- Re-scan after each change to confirm the fix and track your grade over time.
Get the full report + step-by-step fixes
See every finding in detail with AI-generated remediation for api.config-security.com.
View the full report →
Frequently asked questions
Is api.config-security.com safe?
Based on an external ScanLabsAI security scan, api.config-security.com scored B (71/100). api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks. An external scan measures publicly detectable security posture, not internal controls.
What does a B security grade mean?
The B grade reflects the SSL/TLS, security-header, DNS and known-vulnerability checks ScanLabsAI observed from outside api.config-security.com. api.config-security.com is reasonably well configured but has a few issues worth fixing to harden it against common attacks.
How is the api.config-security.com security score calculated?
ScanLabsAI weights findings by severity: critical and high-severity issues reduce the score the most, while common medium and low issues (such as missing security headers) have a smaller impact. The result is a 0–100 score mapped to a letter grade from A+ to F.
How can api.config-security.com improve its security score?
Address the 8 detected issues — starting with the highest severity — then re-scan to confirm. Common quick wins include adding missing security headers and enforcing HTTPS with HSTS.
How this report is produced
ScanLabsAI is an AI-powered website security scanner. This report is generated by a passive external scan — it reads publicly available information the way a visitor would and never attempts to exploit, alter or damage the site. Findings are weighted by severity to produce the 0–100 score and A+–F grade shown above. A grade reflects externally detectable posture and is not a guarantee of overall security.
ScanLabsAI runs a multi-engine security scan (SSL/TLS, security headers, DNS, and known-vulnerability checks) and grades a website's public security posture. Grades reflect issues detectable from the outside and are not a guarantee of overall security.
Scan your own site free → · Security Intel Hub · Claude / MCP