← All free tools
Free tool

Security Headers Grade

We fetch the page ourselves and check the response headers directly — no dependency on a third-party scanner.

FAQ

Which headers does this check?

Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options (or an equivalent frame-ancestors CSP directive), Referrer-Policy, and Permissions-Policy — the six that cover the most common header-based attack classes.

Is this the same as Mozilla Observatory?

Similar idea, run independently: we fetch your page and read the headers ourselves rather than depending on a third-party scanner's uptime.

Want this on autopilot?
Run the full Omnitopical engine on your domain — one plan, $99/mo.
Start