Security Headers
Grade a website's security HTTP headers from A+ to F: HSTS, CSP, X-Frame-Options, Referrer-Policy and more.
About this tool
The tool loads the given page (following redirects) and evaluates the HTTP headers that protect visitors: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy. For each header it explains what is missing and how to fix it. It also flags headers that needlessly reveal the server version.
Glossary
- HSTS
- The Strict-Transport-Security header tells the browser to connect to the website only over HTTPS, even when the user types an http address.
- CSP
- Content-Security-Policy defines where a page may load scripts, styles and images from. It is the main defense against XSS attacks.
- X-Frame-Options and frame-ancestors
- They forbid embedding the page in a frame (iframe) on another website. This prevents clickjacking - tricking users into clicks through an invisible layer.
- X-Content-Type-Options
- The value nosniff forbids the browser from guessing the file type. Without it a browser may, for example, run a text file as a script.
- Referrer-Policy
- Defines how much of the page address the browser reveals to the website a user follows a link to. The recommended value is strict-origin-when-cross-origin.
- Permissions-Policy
- Turns off browser features the website does not need, such as the camera, microphone or location, even for embedded third-party scripts.
- Cross-Origin-Opener-Policy
- Separates the page window from windows opened by other websites. Protects against attacks via window.opener and data leaks between windows.
How to use
- 1Enter the website address.
- 2Click Grade website.
- 3Look at the overall grade and score.
- 4Go through the headers marked with a cross or a half circle.
- 5Add the headers to your server configuration and run the test again.
Specifications and limits
The response of the last page in the redirect chain is graded. Points: HSTS 25, CSP 25, framing protection 15, nosniff 10, Referrer-Policy 10, Permissions-Policy 10, COOP 5. A partial setup earns half the points, each revealed software version deducts 5 points. Grades: A+ from 95, A from 85, B from 70, C from 55, D from 40, E from 25, otherwise F.