Free tool
What grade does your website get for security?
Enter your address. Mozilla's HTTP Observatory scans the security headers your site sends every visitor, and we explain each gap in plain English.
Questions
The security headers your site sends with every page. They tell browsers to insist on HTTPS, which scripts may run, whether other sites may frame your pages, and how cookies are handled. They protect your visitors from a range of attacks, even when the site itself is fine.
Mozilla's HTTP Observatory, a free scanner run by the makers of Firefox. We ask it to scan your site and translate the result. The grade is theirs, not ours, and it is the same one security teams use.
No. It means the site is not using protections that browsers offer. Those protections limit the damage when something else goes wrong, such as a compromised plugin or a third-party script.
Usually. Most of them are headers set on the server or at Cloudflare, not changes to the pages. Content Security Policy takes the most care, because it has to allow every script the site genuinely uses.
Run it and see. We fixed our own headers before building this tool.
Want the grade fixed?
Send us the address. We set the headers without breaking the scripts, forms and analytics your site depends on.
No pitch deck, no obligation. Bring your URL and we will look at it together.