HTTP Security Headers
westlaw.com
Final status: 200
http://westlaw.com (301)http://www.westlaw.com/ (301)https://www.westlaw.com/ (302)https://1.next.westlaw.com/?__lrTS=20260705130621877 (302)https://signon.thomsonreuters.com/?productid=CBT&lr=0&culture=en-US&returnto=https%3a%2f%2f1.next.westlaw.com%2fCosi%2fSignOn&tracetoken=0705260806510LVu2zbzUf0CBodmtvckmVdkrhrMnfmhqvj96L1CORXw8Mwl9Z5mX57pzHVwhezfbElOa7F-cuYKG7qlh5oN9k5jrKIFcKDAk8CDo26XHdPtC06ICSPrLS1mkk3mXl9sfMSbBw0LY0aY4f5mWYfwJFMzb_vOmR2jiNee3cMBlkDhLSEnIqc2ecxzSTYdZDbwnN5XfxowneVhyIPAdvkERTeVYt53KpcxFK3W-jB-eZcbQ2F0VdaZ1TaThINBMAYwB5rLm-Ol8YaL_IIKni4piGk2o05hXGEbNJcytLnVcw_IytPAmUnp9RGu5c7t0CPkjM08v9Ubty03IqZkKmrL7JLLM7i4wbO_ck0jkJrxYIg01exTOybmVfujV8phG2If6 (200)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy strict-origin-when-cross-origin
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.