Scoring methodology
The grade is transparent and points-based — no black box. Every check contributes a number of points; your grade is points earned ÷ points possible.
How points work
Each check has a maximum weighted by how much it matters (a missing Content-Security-Policy costs far more than a missing Cross-Origin-Embedder-Policy). Checks return pass / warn / fail and earn all, some, or none of their points. Purely informational checks contribute 0 points so they never inflate or deflate the grade — they're guidance, not scoring.
Categories
- Transport — HTTPS and HSTS.
- Injection & XSS — a deep Content-Security-Policy evaluation plus X-Content-Type-Options.
- Framing & isolation — clickjacking protection, COOP, CORP, COEP.
- Referrer & permissions — Referrer-Policy and Permissions-Policy.
- Cookies — Secure, HttpOnly, SameSite and prefixes.
- Information disclosure — version banners and deprecated headers.
A stable, comparable grade
Every check has a fixed maximum, and only categories assessable from the response headers alone count toward the letter — so the same headers get the same grade whether you scan the live URL or paste them, and whether the endpoint returns HTML or JSON. Sections that need a live page (subresource integrity, mixed content, security.txt) are shown and scored in their own section but marked not graded, so they never make one site look better or worse than another just because of how it was scanned.
The CSP evaluator
Rather than only checking that a CSP exists, we parse it and score its effectiveness: wildcard/broad script sources, 'unsafe-inline' without a nonce/hash,'unsafe-eval', missing object-src/base-uri/frame-ancestors, use of nonces/hashes and 'strict-dynamic', reporting, and whether the policy is enforced or merely Report-Only.
Grade bands
- A+ — 95% and above
- A — 85% and above
- B — 75% and above
- C — 65% and above
- D — 50% and above
- F — 0% and above
Email, DNS, TLS and WHOIS
These are shown alongside the header grade but scored separately (they describe the domain, not the HTTP response). SPF, DMARC, DKIM, DNSSEC and CAA are checked client-side over DNS-over-HTTPS; WHOIS uses RDAP; TLS reports the certificate and negotiated protocol.
The methodology draws on the OWASP Secure Headers Project and MDN. It is an opinionated best-practice baseline, not a compliance certification.