Security Headers

Grade a website's security HTTP headers from A+ to F: HSTS, CSP, X-Frame-Options, Referrer-Policy and more.

About this tool

The tool loads the given page (following redirects) and evaluates the HTTP headers that protect visitors: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy. For each header it explains what is missing and how to fix it. It also flags headers that needlessly reveal the server version.

Glossary

HSTS
The Strict-Transport-Security header tells the browser to connect to the website only over HTTPS, even when the user types an http address.
CSP
Content-Security-Policy defines where a page may load scripts, styles and images from. It is the main defense against XSS attacks.
X-Frame-Options and frame-ancestors
They forbid embedding the page in a frame (iframe) on another website. This prevents clickjacking - tricking users into clicks through an invisible layer.
X-Content-Type-Options
The value nosniff forbids the browser from guessing the file type. Without it a browser may, for example, run a text file as a script.
Referrer-Policy
Defines how much of the page address the browser reveals to the website a user follows a link to. The recommended value is strict-origin-when-cross-origin.
Permissions-Policy
Turns off browser features the website does not need, such as the camera, microphone or location, even for embedded third-party scripts.
Cross-Origin-Opener-Policy
Separates the page window from windows opened by other websites. Protects against attacks via window.opener and data leaks between windows.

How to use

  1. 1Enter the website address.
  2. 2Click Grade website.
  3. 3Look at the overall grade and score.
  4. 4Go through the headers marked with a cross or a half circle.
  5. 5Add the headers to your server configuration and run the test again.

Specifications and limits

The response of the last page in the redirect chain is graded. Points: HSTS 25, CSP 25, framing protection 15, nosniff 10, Referrer-Policy 10, Permissions-Policy 10, COOP 5. A partial setup earns half the points, each revealed software version deducts 5 points. Grades: A+ from 95, A from 85, B from 70, C from 55, D from 40, E from 25, otherwise F.