PUBLIC OBSERVATION · V1Mon, Aug 17, 2026 5:05 PM

Link Behavior Trace

https://cursor.com/changelog/origin-code-hosting

Observed result Suspicious signals observed 100% observation completeness
Trace another link
SIGNATURE COMPONENT

LINK BEHAVIOR TRACE

0 transition(s)
1
Final
cursor.com https://cursor.com/changelog/origin-code-hosting

Observed signals

4 recorded
Embedded frame observed from a different domain

Observed page structure

LOW
Response cookie observed without the Secure attribute on an HTTPS page

Observed response headers

LOW
Response cookie observed without the HttpOnly attribute

Observed response headers

INFO
Response cookie observed without a SameSite attribute

Observed response headers

INFO

Landing behavior

Observed response
HTTP status200
Content typetext/html
Forms0
Password inputs0
External domains6
Binary responseNo

Security header configuration

Weak
Recommended headers observed2 / 6

Present

strict-transport-securitycontent-security-policy

Not observed

x-frame-optionsx-content-type-optionsreferrer-policypermissions-policy

Response cookies observed

4 cookie(s) observed — 1 without Secure, 4 without HttpOnly, 1 without a SameSite attribute. Cookie names and values are never observed or stored by this scan.

Configuration, not a security guarantee. This describes which response headers were observed, not whether the site is otherwise secure — a "strong" grade means these specific headers were present, nothing more.