Skip to main content

Booking.com

booking.com

64%

Security Score

Last scanned Aug 27, 2026

10

Failed

14

Passed

24

Total Checks

Security Checks (24)

Content Security Policy (CSP)
HeadersCritical
HSTS enabled
HeadersCritical
HTTPS enabled
TLSCritical
TLS Version
TLSCritical
Deprecated TLS versions
TLSCritical
Frame Security Policy
HeadersHigh
Mixed Content
TLSHigh
Set-Cookie headers
HeadersHigh
HTTP to HTTPS Redirect
TLSHigh
Certificate Expiry
TLSHigh
Reverse Tabnabbing Protection
ContentMedium
Trusted Types readiness
HeadersMedium
X-Content-Type-Options header
HeadersMedium
Permissions-Policy header
HeadersMedium
Referrer Policy
HeadersMedium
Cross-Origin Resource Isolation
HeadersMedium
Directory Listing Detection
ContentMedium
Content-Type header
HeadersMedium
Cipher Suite
TLSMedium
Security.txt (RFC 9116)
ContentLow
Robots.txt Security Audit
ContentLow
Server information disclosure
HeadersLow
Deprecated X-XSS-Protection header
HeadersLow
HSTS Preload Readiness
TLSLow

What We Check on Booking.com

TLS / HTTPS Security

We verify that booking.com uses HTTPS with a valid TLS certificate, modern cipher suites, and proper HSTS configuration to protect data in transit.

Security Headers

We check whether booking.com sends critical headers like Content-Security-Policy, X-Frame-Options, and Permissions-Policy to defend against XSS and clickjacking.

Content Security

We scan booking.com for mixed content, vulnerable JavaScript libraries, exposed admin panels, and information disclosure risks.

DNS & Email Security

We validate SPF, DKIM, and DMARC records for booking.com, check DNSSEC, and test for subdomain takeover vulnerabilities.

Scan Your Own Website

See how your site compares to Booking.com. Run a free security scan with 62 checks and get actionable fix instructions.

Start Free Scan

More Travel Security Reports