Free tool

Security Headers Grade

We fetch the page ourselves and check the response headers directly — no dependency on a third-party scanner.

FAQ

Which headers does this check?

Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options (or an equivalent frame-ancestors CSP directive), Referrer-Policy, and Permissions-Policy — the six that cover the most common header-based attack classes.

Is this the same as Mozilla Observatory?

Similar idea, run independently: we fetch your page and read the headers ourselves rather than depending on a third-party scanner's uptime.

Do security headers affect SEO?

Not directly as a ranking factor, but HTTPS itself is a confirmed signal, and headers like HSTS reinforce it. Missing headers are more of a trust and security-hygiene issue — the kind of thing a technical audit flags.

Want this on autopilot?
Run the full Omnitopical engine on your domain — one plan, $99/mo.
Start