Security report for harvard.edu
Free passive scan · WAF/CDN, security headers, TLS, server exposure
F
harvard.edu
Security score 25/100 · No shield detected · 6 missing security headers
What we found
No WAF or CDN detectedHigh
The origin appears directly exposed — no edge firewall filtering OWASP Top 10 attacks, bad bots, or malicious IPs.
Missing HSTSMedium
The HSTS response header is not set.
Missing Content-Security-PolicyMedium
The Content-Security-Policy response header is not set.
Missing X-Frame-OptionsMedium
The X-Frame-Options response header is not set.
Missing X-Content-Type-OptionsLow
The X-Content-Type-Options response header is not set.
Missing Referrer-PolicyLow
The Referrer-Policy response header is not set.
Missing Permissions-PolicyLow
The Permissions-Policy response header is not set.
harvard.edu has no WAF/CDN in front of it and 6 missing security headers — a managed shield can close those (headers via a response-headers policy, not WAF rules).
Protect harvard.edu — $150/mo, fully managedWant your own report? Scan your site free →