SECURITY HEADERS GRADER

Grade your site's HTTP security headers from A+ to F. Detect missing or misconfigured headers with remediation guidance.

URL TO SCAN
QUICK EXAMPLES
ABOUT THIS TOOL

HTTP Security Header Grading

HTTP security headers are a first line of defense against common web attacks. Missing or misconfigured headers expose sites to XSS, clickjacking, MIME-sniffing, and information leakage. This tool grades your site like securityheaders.com — A+ to F — and tells you exactly what to fix.

Grading Algorithm

Each header is weighted by importance. Critical headers like HSTS and CSP carry more weight. The numeric score (0–100) maps to a letter grade: A+ ≥90, A ≥80, B ≥65, C ≥50, D ≥30, F <30.

Headers Checked

  • Strict-Transport-Security — enforces HTTPS, weight: 20
  • Content-Security-Policy — prevents XSS, weight: 20
  • X-Content-Type-Options — prevents MIME sniffing, weight: 15
  • X-Frame-Options — prevents clickjacking, weight: 15
  • Referrer-Policy — controls referrer leakage, weight: 10
  • Permissions-Policy — restricts browser APIs, weight: 10
  • Cross-Origin-Opener-Policy — browser isolation, weight: 5
  • Cross-Origin-Resource-Policy — prevents Spectre attacks, weight: 5