PUBLIC OBSERVATION · V1Tue, Aug 18, 2026 12:00 AM
Link Behavior Trace
https://cursor.com/docs/origin
Observed result
Suspicious signals observed
100% observation completeness
SIGNATURE COMPONENT
LINK BEHAVIOR TRACE
0 transition(s)1
Final
cursor.com
https://cursor.com/docs/origin
Observed signals
4 recordedEmbedded frame observed from a different domain
LOW
Observed page structure
Response cookie observed without the Secure attribute on an HTTPS page
LOW
Observed response headers
Response cookie observed without the HttpOnly attribute
INFO
Observed response headers
Response cookie observed without a SameSite attribute
INFO
Observed response headers
Landing behavior
Observed responseHTTP status200
Content typetext/html
Forms0
Password inputs0
External domains0
Binary responseNo
Security header configuration
PoorRecommended headers observed1 / 6
Present
strict-transport-security
Not observed
content-security-policyx-frame-optionsx-content-type-optionsreferrer-policypermissions-policy
Response cookies observed
1 cookie(s) observed — 1 without Secure, 1 without HttpOnly, 1 without a SameSite attribute. Cookie names and values are never observed or stored by this scan.
Configuration, not a security guarantee. This describes which response headers were observed, not whether the site is otherwise secure — a "strong" grade means these specific headers were present, nothing more.