nih.gov: Security & public interest — week 2026-W30
Security & public interest
Web-standards, metadata, and security checks in the spirit of ScanGov (methodology CC0), run across our scan rather than only the homepage.
Security & domain hygiene 7/8 on the origin
- ✓ Served over HTTPS https:: pass
- ✓ HTTP Strict Transport Security (HSTS): pass
- ✓ Content Security Policy (CSP): pass
- ✓ X-Content-Type-Options: nosniff: pass
- ✓ Clickjacking protection (X-Frame-Options or CSP frame-ancestors): pass
- ✓ Sponsored government TLD (.gov/.mil/.edu) gov: pass
- ✗ Published security.txt: fail
- ✓ Resolves with and without www www.nih.gov: pass
Public interest & sustainability signals origin-level checks
Checks run once per week against the domain origin. ✓ = found/green · ✗ = not found · ~ = uncertain.
| Check | Result | URL | Checked |
| Accessibility statement |
✓ Found (high confidence) |
nih.gov/accessibility |
2026-07-23 |
| carbon.txt |
✗ Not found |
— |
2026-07-23 |
| Renewable hosting (Green Web Foundation) |
✗ Not green |
API response |
2026-07-23 |
| XML sitemap |
✓ Found |
nih.gov/sitemap.xml |
2026-07-23 |
| Human-readable sitemap |
✗ Not found |
— |
2026-07-23 |