Free tool

Security headers

A few lines your server sends with every page protect your visitors against clickjacking, content injection and insecure connections. We read them and give you a grade.

Try with physalisdesign.com, github.com

How the grade works

Each header is worth points: HSTS and CSP 25 each, X-Frame-Options and X-Content-Type-Options 15, Referrer-Policy and Permissions-Policy 10. Showing software versions costs 5 points; a site without HTTPS cannot score above 30.

Where to add them

Apache / .htaccess

Header set

Header always set X-Content-Type-Options "nosniff"

Needs mod_headers, which almost every host enables.

nginx

add_header

add_header X-Content-Type-Options "nosniff" always;

In the server block, or in Plesk under “Additional nginx directives”.

WordPress

Host first

A plugin can add them, but the server does it faster and for every file.

Many hosts have a “security headers” setting.