PUBLIC OBSERVATION · V1Mon, Aug 17, 2026 5:05 PM
Link Behavior Trace
https://cursor.com/changelog/origin-code-hosting
Observed result
Suspicious signals observed
100% observation completeness
SIGNATURE COMPONENT
LINK BEHAVIOR TRACE
0 transition(s)1
Final
cursor.com
https://cursor.com/changelog/origin-code-hosting
Observed signals
4 recordedEmbedded frame observed from a different domain
LOW
Observed page structure
Response cookie observed without the Secure attribute on an HTTPS page
LOW
Observed response headers
Response cookie observed without the HttpOnly attribute
INFO
Observed response headers
Response cookie observed without a SameSite attribute
INFO
Observed response headers
Landing behavior
Observed responseHTTP status200
Content typetext/html
Forms0
Password inputs0
External domains6
Binary responseNo
Security header configuration
WeakRecommended headers observed2 / 6
Present
strict-transport-securitycontent-security-policy
Not observed
x-frame-optionsx-content-type-optionsreferrer-policypermissions-policy
Response cookies observed
4 cookie(s) observed — 1 without Secure, 4 without HttpOnly, 1 without a SameSite attribute. Cookie names and values are never observed or stored by this scan.
Configuration, not a security guarantee. This describes which response headers were observed, not whether the site is otherwise secure — a "strong" grade means these specific headers were present, nothing more.