Editorial author: XRENN Labs s.r.o. · Updated:
CSP and browser capabilities solve different problems
Content-Security-Policy constrains permitted resource sources and other browser behavior. Permissions-Policy controls whether features such as camera or geolocation are available in a document and its frames, subject to browser support. Their presence alone says little about whether the chosen directives match your application.
Sources: MDN — Content-Security-Policy · MDN — Permissions-Policy
What our scanner measures
We request public web responses, follow permitted redirects and try alternative domain endpoints within the scan budget. The report identifies the observed endpoint and security headers. A successful response can be assessed; headers on an access-controlled response remain limited evidence. We do not bypass sign-in to inspect private pages.
Presence is not a browser security audit
One response does not represent every route, API, cache variant or error page. A CSP header may still allow overly broad sources. The scanner does not simulate every browser interaction or prove the absence of XSS. Its grade is a XRENN™ assessment, not a Mozilla Observatory result.
Deploy through observation and testing
Inventory scripts, styles, frames and API connections, including payment, consent and sign-in components. A CSP Report-Only policy can expose violations before enforcement; it does not itself block the violating activity. Review reports, then enforce a tailored policy. Grant only the browser capabilities the service actually needs, and check embedded content too.
Sources: MDN — Content-Security-Policy · MDN — Permissions-Policy
Re-scan and exercise real user journeys
Check the response headers after deployment and after any CDN cache refresh. Then test mobile and desktop sign-in, form validation, submission and third-party components with their intended consent settings. A higher header score cannot replace those functional checks or application testing.
Editorial method and primary sources
These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.