28security features with a direct test link
2features without a reliable direct test link
af38980dreviewed test-source revision
2026-07-23date the links were reviewed
Feature-by-feature links

Relevant browser tests

“Reviewed test source” opens the exact version checked for this site. “Latest public results” opens the live results, which can change over time.

Content executionTest link available

Content Security Policy

Policy parsing and enforcement behaviour across the CSP test suite.

Limit: Suite coverage does not establish that an application's policy is complete, effective, or deployed on every response.

Content executionTest link available

CSP nonce sources

Nonce source parsing and script authorisation behaviour.

Limit: The mapping covers browser behaviour, not nonce unpredictability, per-response generation, reuse, or disclosure.

Content executionTest link available

CSP strict-dynamic

strict-dynamic parsing, trust propagation, and fallback interactions.

Limit: Passing behaviour does not establish that an application's trusted loaders are safe.

Content executionTest link available

CSP frame-ancestors restriction

Embedding authorisation across same-origin, cross-origin, nested, and sandboxed cases.

Limit: The mapping does not establish that the deployed allowlist matches an application's intended embedding relationships.

Content executionTest link available

CSP form-action restriction

Form destination authorisation, redirects, and target behaviour.

Limit: The suite does not evaluate scripted requests, server authorisation, or whether every legitimate destination was inventoried.

Content executionTest link available

CSP sandbox

Sandbox token behaviour across frames, workers, redirects, and navigations.

Limit: The suite cannot determine whether an application's selected sandbox tokens grant excessive capability.

Content executionTest link available

Subresource Integrity

Integrity metadata parsing, digest matching, fetching, and CSP interactions.

Limit: The suite does not establish that a deployment supplies current integrity metadata for every eligible resource.

Content executionTest link available

Subresource Integrity Policy

Integrity-Policy parsing, blocking, report-only behaviour, destinations, sources, and reporting integration.

Limit: The suite does not establish that every production resource carries current metadata or that reports are operationally reviewed.

Cross-origin isolationTest link available

Cross-Origin-Opener-Policy

Browsing-context isolation, opener relationships, reporting, and navigation behaviour.

Limit: The mapping does not establish compatibility with an application's popup and cross-window integrations.

Cross-origin isolationTest link available

Origin-Agent-Cluster

Origin-keyed agent-cluster opt-in and browsing behaviour.

Limit: Agent clustering is not a guarantee of process isolation or an application authorisation boundary.

Browser privacyTest link available

Permissions Policy

Policy parsing, inheritance, delegation, and feature-specific enforcement.

Limit: The suite does not establish that an application selected the correct capabilities or frame allowlists.

Transport and response hardeningNo exact test link

HTTP Strict Transport Security

No exact suite mapping was retained at the reviewed revision.

No similar test is substituted when an exact link is unavailable.

Limit: Nearby HTTPS and navigation tests are not substituted for HSTS state, expiry, subdomain, or first-visit behaviour.

Transport and response hardeningTest link available

Clear-Site-Data

Directive parsing and browser-held data clearing behaviour.

Limit: The mapping does not establish correct logout sequencing, server-side revocation, or coverage of every storage mechanism.

Browser privacyTest link available

Referrer Policy

Policy parsing and referrer delivery across navigation and resource contexts.

Limit: The suite does not establish that sensitive data is absent from URLs or other telemetry.

Browser privacyTest link available

SameSite cookies

SameSite parsing and cookie delivery across same-site and cross-site contexts.

Limit: The mapping does not establish that session cookies use an appropriate value or replace CSRF protection.

Browser privacyTest link available

Partitioned cookies

Partition-key behaviour, redirects, subresources, and SameSite interactions.

Limit: The mapping does not establish that a deployment needs partitioned state or declares all required attributes.

Browser privacyNo exact test link

HttpOnly cookies

No exact suite mapping was retained at the reviewed revision.

No similar test is substituted when an exact link is unavailable.

Limit: General cookie tests are not substituted for the intended claim that script access is prevented by HttpOnly.

Browser privacyTest link available

Secure cookie prefixes

__Secure-, __Host-, __Http-, and __Host-Http- prefix constraint behaviour.

Limit: Prefix enforcement does not establish sound session design or protection from every cookie-confusion attack.

AuthenticationTest link available

WebAuthn PRF extension

PRF extension parsing and credential operation behaviour within the WebAuthn suite.

Limit: The mapping does not establish authenticator support in a user's environment or a safe key-recovery design.

How the information fits together

Browser support, public tests, and your own evidence answer different questions

MDN data records which browsers support a feature. Web Platform Tests exercise standard browser behaviour. ControlCurrent can also check configuration information that you supply. None of these can see the full security design of a production website.

Why there is no simple test score

ControlCurrent does not turn live public test results into a percentage. The selected tests, browser version, test infrastructure, expected failures, and incomplete runs all need context that a single score would hide.

Some Web Platform Tests (WPT) also require automation and cannot be run in an ordinary browser session.