The following sites are used to scan your website and make recommendations for optimizing and speeding up your website: http://gtmetrix.com/ http://tools.pingdom.com/fpt/ http://www.webpagetest.org/ https://developers.google.com/speed/pagespeed/insights/ The following is a good
https://www.hardenize.com https://www.gravityscan.com https://www.ssllabs.com/ssltest/ https://wpscans.com https://pentest-tools.com/home http://www.ipfingerprints.com/portscan.php https://www.subnetonline.com/pages/ipv6-network-tools/online-ipv6-port-scanner.php https://portmap.com/ Other scanners based on headers or dnssec only on other pages in this site
https://observatory.mozilla.org/ https://securityheaders.io/ https://report-uri.io/home/tools https://csp-evaluator.withgoogle.com/ https://cspvalidator.org/#url=https://cspvalidator.org/ Chrome Extension to test CSP without actually applying it to the website: https://chrome.google.com/webstore/detail/caspr-enforcer/fekcdjkhlbjngkimekikebfegbijjafd?hl=en-US https://www.gravityscan.com/ Example Header for nginx [crayon-673ed41abc2ff088596144/]