Steps to improve eff.org's security grade, ranked by impact.
The HSTS header is missing on eff.org. Without it, connections can be downgraded from HTTPS to HTTP via man-in-the-middle attacks. This is a straightforward server configuration change.
eff.org scored 55/100 and does not currently meet the minimum security posture threshold. Multiple configuration gaps were identified that require attention before approval.
Critical gaps in: HSTS Header, Security Headers. Positive signals: DNS CAA Records, Known Breaches, Cookie Security all passed.
6 action items identified, including 0 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2678 companies we've scanned. eff.org scores better than 17% of them.
Key data points from the scan.
Other domains with comparable security profiles.