Grades any site's HTTP security headers — CSP, HSTS, X-Frame-Options, and more — with weighted scoring and per-header explanations. Fetching happens server-side, hardened against SSRF (private/reserved IP blocking, standard ports only, redirect revalidation).
view source on GitHub ↗grades a site's HTTP security headers — CSP, HSTS, framing, sniffing, referrer & permissions policy