← All free tools
Free tool
Security Headers Grade
We fetch the page ourselves and check the response headers directly — no dependency on a third-party scanner.
FAQ
Which headers does this check?
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options (or an equivalent frame-ancestors CSP directive), Referrer-Policy, and Permissions-Policy — the six that cover the most common header-based attack classes.
Is this the same as Mozilla Observatory?
Similar idea, run independently: we fetch your page and read the headers ourselves rather than depending on a third-party scanner's uptime.
Want this on autopilot?
Run the full Omnitopical engine on your domain — one plan, $99/mo.