Skip to main content

World Health Organization

who.int

58%

Security Score

Last scanned Aug 27, 2026

10

Failed

14

Passed

24

Total Checks

Security Checks (24)

Content Security Policy (CSP)
HeadersCritical
HSTS enabled
HeadersCritical
HTTPS enabled
TLSCritical
TLS Version
TLSCritical
Deprecated TLS versions
TLSCritical
Frame Security Policy
HeadersHigh
Set-Cookie headers
HeadersHigh
HTTP to HTTPS Redirect
TLSHigh
Certificate Expiry
TLSHigh
Mixed Content
TLSHigh
Reverse Tabnabbing Protection
ContentMedium
Trusted Types readiness
HeadersMedium
Permissions-Policy header
HeadersMedium
Cross-Origin Resource Isolation
HeadersMedium
Directory Listing Detection
ContentMedium
X-Content-Type-Options header
HeadersMedium
Content-Type header
HeadersMedium
Referrer Policy
HeadersMedium
Cipher Suite
TLSMedium
Security.txt (RFC 9116)
ContentLow
Deprecated X-XSS-Protection header
HeadersLow
HSTS Preload Readiness
TLSLow
Robots.txt Security Audit
ContentLow
Server information disclosure
HeadersLow

What We Check on World Health Organization

TLS / HTTPS Security

We verify that who.int uses HTTPS with a valid TLS certificate, modern cipher suites, and proper HSTS configuration to protect data in transit.

Security Headers

We check whether who.int sends critical headers like Content-Security-Policy, X-Frame-Options, and Permissions-Policy to defend against XSS and clickjacking.

Content Security

We scan who.int for mixed content, vulnerable JavaScript libraries, exposed admin panels, and information disclosure risks.

DNS & Email Security

We validate SPF, DKIM, and DMARC records for who.int, check DNSSEC, and test for subdomain takeover vulnerabilities.

Scan Your Own Website

See how your site compares to World Health Organization. Run a free security scan with 62 checks and get actionable fix instructions.

Start Free Scan

More Government Security Reports