Scoring

SSL Labs

alt text

Mozilla Observatory

alt text

Additional Score Commentary:

Mozilla Observatory

Current CSP requires the use of unsafe-eval and unsafe-inline for script-src.

Current CSP requires the use of unsafe-inline for style-src.

The relevant issue can be found at: https://github.com/go-gitea/gitea/issues/305

This scores a -20 in Mozilla Observatory.