Substack
substack.com
Checks Passed
Warnings
Failed Issues
Total Evaluated
Category Score Breakdown
Security Topology Tree — substack.com
Interactive node visualization showing security controls, certificates, headers, and risk posture.
Audited Security Controls (8)
HTTPS Enforcement & Modern TLS
Verifies encrypted transport, cipher strength, and absence of legacy protocols.
Fix: Maintain TLS 1.3 with forward secrecy.
Strict-Transport-Security (HSTS)
Forces modern browsers to communicate exclusively over HTTPS.
Fix: Configure max-age >= 31536000 with includeSubDomains.
Content Security Policy (CSP)
Restricts sources from which scripts and styles can load to prevent XSS.
Fix: Adopt strict-dynamic nonces and eliminate unsafe-inline.
Clickjacking Protection (X-Frame-Options)
Guards against clickjacking and UI redressing attacks.
Fix: Set X-Frame-Options to DENY or SAMEORIGIN.
Cookie Security Flags (HttpOnly & Secure)
Protects session tokens from theft via client-side scripts.
Fix: Mark all session cookies HttpOnly and Secure.
Email Spoofing Defense (SPF & DMARC)
Validates SPF and DMARC enforcement to prevent domain impersonation.
Fix: Enforce DMARC p=quarantine or p=reject.
Public Secrets & Sensitive File Exposure
Probes for .env, .git, backups, and exposed credentials in client bundles.
Fix: Clean scan: no leaked keys or exposed files found.
Subdomain Takeover & CNAME Radar
Audits DNS records for dangling pointers to abandoned cloud services.
Fix: No dangling DNS records detected.
Protect your production site against configuration drift. Igris Radar can audit substack.com daily and notify your team via Slack or Email if a certificate expires or headers are removed.