2016-09-01, 04:13:20
(2016-09-01, 02:10:56)sremick Wrote: Thoughts?
Yes, it's a very buggy test. For my site, it says – correctly – that HSTS is not implemented (I have .htaccess rules that redirect http requests to https) and then says that the site doesn't support https. I score an 'F'.
The fact that it gets fundamental stuff wrong makes me doubt its advice. Typical web junk written by new graduates, if I had to guess. google.com, the headquarters of the self-appointed web security police, only scores a 'D'.
Meanwhile, admittedly for a different suite of tests, ssllabs.com gives me an 'A'.
--
Nick.
Nick.