Free tools

Security headers grade

We load the page, follow its redirects and grade the final response's HTTPS and security headers, with what to fix first.

Good to know

Which header matters most?
Strict-Transport-Security, so browsers always use HTTPS, and Content-Security-Policy, which limits where scripts can load from and blunts cross-site scripting.
Can I set these without touching my app?
Usually yes: add them in your web server (nginx, Apache), your hosting platform's settings (Vercel, Netlify) or your CDN (Cloudflare Transform Rules).
Why do version numbers in headers matter?
Server: nginx/1.18.0 or X-Powered-By: PHP/7.4 tell attackers exactly which known vulnerabilities to try. Hide the versions.

Get told the moment it breaks

Checking by hand only tells you about right now. Spot Downtime checks your sites around the clock and alerts you by email, Slack or Discord.

Start monitoring free