Summary of checkout.stripe.com [Desktop version] Website Security Test
Provided "as is" without any warranty of any kind.
Date/Time:Mar 28th, 2025 17:09 GMT+0
Server IP:3.168.122.54
Reverse DNS:server-3-168-122-54.jfk52.r.cloudfront.net
Location:N/A, United States
Version:for desktop
Your final score:
- A
- B
- C
- F
A
This test was made 371 days ago and may be outdated
Refresh Test
Executive Summary for checkout.stripe.com
- 2 third-party web software dependancies were identified, including one outdated dependancy. No known vulnerabilities were detected. No Content Management System (CMS) was identified. The following CMS components, JS-libraries or frameworks were identified: react, lodash. Show details.
- No obvious GDPR-related compliance issues were detected across Privacy Policy, Website Security, TLS Encryption, Cookie Protection, Cookie Disclaimer. The following checks were not performed, as no corresponding cookies with personal or tracking information seem to be sent by the website: Cookie Protection, Cookie Disclaimer. Show details.
- The website is compliant with PCI DSS Requirement 6.3, while being non-compliant with Requirement 6.4. Show details.
- Issues were identified with key security headers: missing X-Frame-Options; misconfigured Content-Security-Policy. Optional HTTP headers appear to be properly configured: Server, Access-Control-Allow-Origin, Cache-Control. Show details.
- Content-Security-Policy is enforced but configuration issues were identified: overly permissive directives, deprecated directives. A report-only Content-Security-Policy is not present. Show details.
- No cookies were detected. Show details.
- 7 external requests detected; all requests completed successfully. SRI is not used for 6 third-party JavaScript and CSS files. Show details.
- No significant anti-scraping protections were detected. Show details.
- DNS CNAME record detected; DNSSEC signatures are not present. Show details.


