All tools

HTTP Security Headers Scorecard

Network

Score a pasted block of raw HTTP response headers against commonly recommended security headers, with an overall 0-100 score and A-F grade

Paste a block of raw HTTP response headers and get a quick scorecard against the headers security scanners check first: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the three Cross-Origin-* isolation headers. Each one is flagged pass, warning, or missing, with a plain-English note explaining the risk or the specific weakness found, like a CSP that still allows unsafe-inline or an HSTS max-age under a year. It rolls everything up into a single 0-100 score and A-F letter grade so you can see at a glance whether a response is well hardened or needs work. This evaluates exactly the header text you paste, not a live request, and each check is intentionally shallow: it does not replace a header's own dedicated builder tool (like the CSP Header Builder) for validating that header's directives in depth.

httpheaderssecurityscorecardcsphsts

How to use HTTP Security Headers Scorecard

  • 1.Paste a block of response headers, one "Name: value" pair per line, copied from your browser's network tab or a curl -I response.
  • 2.Check the grade and score for a quick read on overall hardening, then scan the per-header table for anything flagged missing or warning.
  • 3.Follow up on a flagged header with its own dedicated builder tool (CSP Header Builder, HSTS Header Builder, etc.) for a deeper check of that header's directives.

Frequently asked questions

Does this fetch my site's actual headers?
No, there are no live network calls: paste the header text you already have (from your browser's dev tools, curl -I, or any other source) and it's scored exactly as given.
Why did a header I set still get flagged as a warning?
Each check looks for a specific common weakness, not just presence: for example, Strict-Transport-Security is flagged as a warning if its max-age is under a year, and Content-Security-Policy is flagged if it includes unsafe-inline or unsafe-eval, even though both headers are technically present.
Is this the same as Mozilla Observatory or securityheaders.com?
It checks a similar set of headers but is deliberately simpler: it evaluates header text you paste rather than scanning a live URL, and it doesn't replicate every rule those tools check.
What does the score actually measure?
Each of the 9 checks counts for one point if it passes, half a point if it's a warning, and zero if missing; the score is that total as a percentage, with a letter grade banded from it (90+ is A, 75+ is B, and so on down to F).

Use via API, SDK, or MCP

cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/security-headers-scorecard \
  -H "Authorization: Bearer utx_live_..." \
  -H "Content-Type: application/json" \
  -d '{"headers":"Content-Security-Policy: default-src 'self'\nStrict-Transport-Security: max-age=63072000\nX-Content-Type-Options: nosniff"}'

Get an API key from your dashboard · Full API docs →