So many websites with no best practices....

Example, a website that tries to be secure, is non-malicious or suspicious as such, but fails higher security standards.

Where? Here for example: https://sritest.io/#report/cacd4024-9a8f-4412-bc30-a09dd2332107

Let’s Encrypt Authority X3 certificate properly installed,
but issues here with a F-F-I-X and A and A+ status:
https://observatory.mozilla.org/analyze.html?host=www.intendit.se

27 sources and 84 sinks found: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.intendit.se

We should always encourage websites to improve on website security standards (e.g. same origin policy etc.)
to be able to further a more secure infrastructure as a whole…

polonus (volunteer website security analyst and website error-hunter)