HTTP Security Headers Scorecard
NetworkScore a pasted block of raw HTTP response headers against commonly recommended security headers, with an overall 0-100 score and A-F grade
Paste a block of raw HTTP response headers and get a quick scorecard against the headers security scanners check first: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the three Cross-Origin-* isolation headers. Each one is flagged pass, warning, or missing, with a plain-English note explaining the risk or the specific weakness found, like a CSP that still allows unsafe-inline or an HSTS max-age under a year. It rolls everything up into a single 0-100 score and A-F letter grade so you can see at a glance whether a response is well hardened or needs work. This evaluates exactly the header text you paste, not a live request, and each check is intentionally shallow: it does not replace a header's own dedicated builder tool (like the CSP Header Builder) for validating that header's directives in depth.
How to use HTTP Security Headers Scorecard
- 1.Paste a block of response headers, one "Name: value" pair per line, copied from your browser's network tab or a curl -I response.
- 2.Check the grade and score for a quick read on overall hardening, then scan the per-header table for anything flagged missing or warning.
- 3.Follow up on a flagged header with its own dedicated builder tool (CSP Header Builder, HSTS Header Builder, etc.) for a deeper check of that header's directives.
Frequently asked questions
Use via API, SDK, or MCP
cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/security-headers-scorecard \
-H "Authorization: Bearer utx_live_..." \
-H "Content-Type: application/json" \
-d '{"headers":"Content-Security-Policy: default-src 'self'\nStrict-Transport-Security: max-age=63072000\nX-Content-Type-Options: nosniff"}'Get an API key from your dashboard · Full API docs →