Steps to improve manus.im's security grade, ranked by impact.
The HSTS header is missing on manus.im. Without it, connections can be downgraded from HTTPS to HTTP via man-in-the-middle attacks. This is a straightforward server configuration change.
manus.im scored 78/100, meeting baseline requirements but with 5 findings that require attention. The vendor can proceed with a remediation timeline agreement.
Critical gaps in: HSTS Header, Security Headers. Positive signals: DMARC / Email Security, TLS Protocol Support, TLS Configuration all passed.
3 action items identified, including 0 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2678 companies we've scanned. manus.im scores better than 59% of them.
Key data points from the scan.
Other domains with comparable security profiles.