Free tool
Security headers
A few lines your server sends with every page protect your visitors against clickjacking, content injection and insecure connections. We read them and give you a grade.
How the grade works
Each header is worth points: HSTS and CSP 25 each, X-Frame-Options and X-Content-Type-Options 15, Referrer-Policy and Permissions-Policy 10. Showing software versions costs 5 points; a site without HTTPS cannot score above 30.
Where to add them
Apache / .htaccess
Header set
Header always set X-Content-Type-Options "nosniff"
Needs mod_headers, which almost every host enables.
nginx
add_header
add_header X-Content-Type-Options "nosniff" always;
In the server block, or in Plesk under “Additional nginx directives”.
WordPress
Host first
A plugin can add them, but the server does it faster and for every file.
Many hosts have a “security headers” setting.