๐ Security Score
Rule-based, from real headersNot scanned yet
Run a check to see this site's security header score.
Analyze HTTP security headers, review missing protections, and understand how well a website is protected against common browser-based vulnerabilities — fetched and scored by our own backend, never faked in the browser.
Run a check to see this site's security header score.
| Header | Status | Value | Description |
|---|---|---|---|
| Run a check to see this site's security headers. | |||
Run a check to see this site's overall security grade.
Security headers are HTTP response headers that help protect a website from common attacks and browser-related vulnerabilities.
Check fetches the target URL from our own server with the same SSRF protections used across our tools (private/loopback/link-local/metadata addresses are always rejected), following redirects to see whether HTTP is upgraded to HTTPS. It inspects 16 real response headers, parses Set-Cookie flags, and independently opens a TLS connection to read the negotiated protocol version and cipher suite — including whether that cipher suite provides forward secrecy. The score and grade are computed from these real signals, never randomly generated.
Yes. It's read from the real TLS handshake's negotiated cipher suite: TLS 1.3 suites are always forward-secret, and for TLS 1.2 it's true only for (EC)DHE key-exchange suites.
Disclosing or hiding server software is a deliberate choice either way โ it's shown for reference but doesn't count toward the pass/warning/missing summary.
They're scored the same way modern scanners commonly present them, but the description for each explains plainly that it's legacy, so the number doesn't overstate real risk.
No. Requests that resolve to localhost, private IP ranges, link-local addresses or cloud metadata endpoints are rejected before any fetch happens.
No. Each scan runs live for your request only. The exported report is generated and downloaded entirely in your browser.