Security Header Scanner
Fetch any URL from Cloudflare’s edge and grade the HTTP security headers it returns (A–F) across 8 core headers — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, CORP, COOP and Permissions-Policy.
Fetches the URL from Cloudflare's edge and grades the security headers it returns. Grade counts 8 core headers — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, CORP, COOP, Permissions-Policy. See the security headers reference for what each one does.
Grades a live website
Fetch example.com from Cloudflare’s edge and grade the security headers it returns, showing which core headers are present and which are missing.
Requires an internet connection. The fetch happens server-side from Cloudflare’s edge.
FAQ
What does the grade mean?
The score counts how many of 8 core headers are present, mapped to a grade: 7–8 is an A, 5–6 a B, 3–4 a C, 1–2 a D, and none an F.
Which headers count as core?
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, CORP, COOP and Permissions-Policy. See the Security Headers reference for what each does.
Why might another scanner disagree?
Different scanners count different header sets and fetch from different geo-locations, and some sites serve different headers by region or device. Treat grades as indicative, not absolute.
Is it safe to scan a URL I don’t own?
This performs a normal HTTP GET just like a browser would, but be considerate and scan sites you have permission to test. It does not exploit or modify anything.