3 ms·
Here is a more comprehensive website testing tool. https://www.validbot.com https://www.validbot.com Full disclosure, this is my project.
by offsky 5y ago
Here is a more comprehensive website testing tool.
https://www.validbot.com https://www.validbot.com
Full disclosure, this is my project.
- chrismorgan 5y agoTried it on my site: https://www.validbot.com/report/b6c2b0aec340f6133de16148a495d5d2e https://www.validbot.com/report/b6c2b0aec340f6133de16148a495... Some of the icon tests are bogus. I deliberately don’t put any <link rel=icon> on my site, but have a favicon.ico containing (among other sizes) 16×16 and 32×32. Your tool complains about meta tags for 16×16 and 32×32 not being found in the HTML. Well, they’re not, but they’re not necessary, because I haven’t put anything in place that would disrupt the favicon.ico fallback. 192×192: … why? Won’t things gladly scale that 512×512 you want down? Manifest and other large icon sizes: this stuff isn’t relevant to all sites. And that’s a problem with these sorts of tools in general, they give scores tuned to a single usage profile which simply isn’t suitable in all cases. As with HTTP Observatory’s XSS stuff commented about elsewhere in this thread. What we need for tools like this is profiles that twiddle rankings. Things like “personal content site” which changes manifest and Apple/Safari/large icons to optional. As it stands, the weighting of this extra stuff is way off base—I get given an F for that section, when I honestly think it should get at least an A, when operating under my hypothetical “personal content site” profile. Test 48 is bogus, the <body> start tag is optional. Test 111, wanting initial-scale on the viewport meta tag, I’ve been casually searching for someone to confirm what it actually does, and if it’s still needed. Most indications suggest it was basically a workaround for an ancient iOS Safari rotation bug, but I’ve come across at least one person stating (without detail) that it still did something. Any chance you have Apple stuff and can investigate more as to whether it’s actually still at all useful? Test 33, DMARC record formatting, looks bogus.
- offsky 5y agoNo general purpose testing tool like this can be a one-size-fits-all sort of thing. In the future I plan on adding configuration options so you can disable tests that you don't care about. If you know what you are doing, but all means feel free to disregard any tests that you don't agree with. The suggestions that Validbot makes are meant to be general purpose "best practices" to help web developers make sure they are paying attention to everything they should be. Sounds like you are and have made some good decisions.
- edoceo 5y agoWhy do you want to make TTLs on some things one day? You think an hour is too short?
- offsky 5y agoFor some reason TTL recommendations seem to cause heated debates. In my opinion, it really depends on what sort of website you are making. A Google type website will need different TTLs (among other things) than a personal blog. The point really is to think about it and make a conscious decision instead of just accepting the defaults that your DNS provider uses. I think 1 hour is just fine.
- Seirdy 5y agoGreat tool. Some feedback: - The section on FLOC is a bit inaccurate; I wrote about what the interest-cohort permis. policy does and doesn't do: https://seirdy.one/2021/04/16/permissions-policy-floc-misinfo.html https://seirdy.one/2021/04/16/permissions-policy-floc-misinf... - Safari now supports normal icons for pinned tabs. apple.com no longer uses a mask-icon. - X-XSS-PROTECTION should be set to 0 (disable) according to OWASP's latest guidelines, since XSS filtering has been found to introduce new sec vulns: https://owasp.org/www-project-secure-headers/#x-xss-protection https://owasp.org/www-project-secure-headers/#x-xss-protecti... - Some implementations of HSTS and auto HTTPS upgrades mandate that HTTP-to-HTTPS redirects don't change the hostname, including the www prefix. If anything, this tool should recommend against a single redirect for HTTP->HTTPS upgrades and www subdomain prefixing/removal. - Very, very few browsers do support X-Frame-Options but lack support for CSP; even fewer have a modern TLS stack that works with secure cipher suites. X-Frame-Options no longer should be needed since the CSP header fills its use case. I'd recommend taking a look at some existing checkers for reference. Webbkoll, check-your-website.server-daten.de, Hardenize, Lighthouse, and Webhint.io are some good ones.