SECURITY HEADERS GRADER
Grade your site's HTTP security headers from A+ to F. Detect missing or misconfigured headers with remediation guidance.
URL TO SCAN
QUICK EXAMPLES
ABOUT THIS TOOL
HTTP Security Header Grading
HTTP security headers are a first line of defense against common web attacks. Missing or misconfigured headers expose sites to XSS, clickjacking, MIME-sniffing, and information leakage. This tool grades your site like securityheaders.com — A+ to F — and tells you exactly what to fix.
Grading Algorithm
Each header is weighted by importance. Critical headers like HSTS and CSP carry more weight. The numeric score (0–100) maps to a letter grade: A+ ≥90, A ≥80, B ≥65, C ≥50, D ≥30, F <30.
Headers Checked
- Strict-Transport-Security — enforces HTTPS, weight: 20
- Content-Security-Policy — prevents XSS, weight: 20
- X-Content-Type-Options — prevents MIME sniffing, weight: 15
- X-Frame-Options — prevents clickjacking, weight: 15
- Referrer-Policy — controls referrer leakage, weight: 10
- Permissions-Policy — restricts browser APIs, weight: 10
- Cross-Origin-Opener-Policy — browser isolation, weight: 5
- Cross-Origin-Resource-Policy — prevents Spectre attacks, weight: 5