Security Headers Grade Calculator
Configure your HTTP security header values to instantly calculate a security grade from A+ to F. Our security headers grade calculator evaluates HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and CORS headers with a weighted scoring system. Get detailed findings and actionable recommendations for each header - all processing happens locally in your browser with no data uploads.
Configure your HTTP security header values from the dropdowns below to instantly calculate your security grade. Each header is scored based on its configuration, and the overall grade (A+ to F) reflects your website's security posture. All processing happens locally in your browser.
Configure Security Headers
Forces HTTPS connections and prevents SSL stripping attacks.
Controls which resources can be loaded, preventing XSS attacks.
Prevents clickjacking by controlling framing of the page.
Prevents MIME-sniffing vulnerabilities.
Controls referrer information sent in cross-origin requests.
Restricts access to browser APIs like geolocation, camera, etc.
Controls cross-origin resource sharing.
Select security header configurations above
Choose values from each dropdown to calculate your security grade
Why Use Our Security Headers Grade Calculator?
A+ to F Security Grading
Get an instant letter grade (A+ to F) for your HTTP security header configuration. The grade is calculated using a weighted scoring system that evaluates each header based on its importance - HSTS and CSP are weighted highest, followed by X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and CORS.
Detailed Header-by-Header Scoring
Each security header is scored individually with a clear breakdown of why it received that score. The calculator evaluates specific configurations like HSTS max-age and includeSubDomains, CSP unsafe-inline detection, X-Frame-Options values, and Permissions-Policy restrictions - with findings and recommendations for every header.
Pre-built Configuration Presets
Choose from curated dropdown options for each header, ranging from "not configured" to best-practice configurations. Each option shows its score contribution and a description of the security posture. This makes it easy to experiment with different configurations and see how each choice affects your grade.
100% Local Processing
All grading calculations happen locally in your browser using pure JavaScript. The header configurations you select never leave your device - no data is uploaded, no logs are stored, and no server-side processing occurs. Completely safe for evaluating security configurations of any website.
Common Use Cases for Security Headers Grade Calculator
Security Audit & Compliance
During security audits, use the grade calculator to evaluate the HTTP security header configuration of your websites. Identify missing or misconfigured headers that could lead to vulnerabilities like XSS, clickjacking, MIME-sniffing, or SSL stripping. Track progress as you improve your security posture over time.
Pre-Deployment Configuration Testing
Before deploying header configuration changes to production, test different combinations in the calculator to see how they affect your grade. This helps you find the optimal balance between security and functionality without affecting live traffic.
Infrastructure Hardening
When hardening web servers, CDNs, or application gateways, use the calculator to verify that all recommended security headers are properly configured. The detailed findings and recommendations help you systematically address each header until you achieve an A+ grade.
Vulnerability Remediation
When vulnerability scanners report missing or weak security headers, use the calculator to quickly try different configurations and find the right fix. The grade shows you exactly which headers need attention and how to configure them for maximum security.
Learning HTTP Security Headers
Use the calculator as an educational tool to understand how different HTTP security headers work together. Experiment with various configurations, learn what each header does, and see how different choices (like using unsafe-inline in CSP vs not using it) affect the overall security grade.
Security Baseline Definition
Define a security baseline for your organization by determining the minimum header configuration required to achieve your target grade. Use this baseline in your CI/CD pipeline to automatically reject deployments that degrade your security header posture.
Understanding HTTP Security Headers Grading
What is HTTP Security Headers Grading?
HTTP security headers grading is the process of evaluating the security-related HTTP response headers that a website sends to browsers. These headers control critical security behaviors like enforcing HTTPS (HSTS), preventing XSS attacks (CSP), blocking clickjacking (X-Frame-Options), preventing MIME-sniffing (X-Content-Type-Options), controlling referrer information (Referrer-Policy), and restricting browser API access (Permissions-Policy). The grade reflects how well a website is protected against common web vulnerabilities through its header configuration, with A+ representing the highest level of protection.
How Our Security Headers Grade Calculator Works
- Select configurations: Choose the value for each security header from the dropdown options. Each option represents a real-world configuration, from not configured to best-practice settings. The options include descriptions that explain the security impact of each choice.
- Calculate scores: Each header is scored independently using a specialized scoring function that understands the specific security implications of different configurations. For example, HSTS scoring evaluates max-age duration, includeSubDomains presence, and preload readiness. CSP scoring checks for unsafe-inline, unsafe-eval, wildcard sources, and proper directive configuration.
- View grade and findings: The individual header scores are summed to produce a total score out of 105 possible points. This total is converted to a letter grade (A+ to F) and displayed with color-coded badges. Each header card shows its score, findings, and a specific recommendation for improvement when applicable.
Key HTTP Security Headers Evaluated
- Strict-Transport-Security (HSTS): Forces browsers to always use HTTPS. Scored on max-age duration (25 pts) - 1 year+ gets highest marks, plus bonuses for includeSubDomains and preload.
- Content-Security-Policy (CSP): Controls allowed content sources to prevent XSS. Scored on absence of unsafe-inline/unsafe-eval (13 pts), wildcard sources (4 pts), object-src (3 pts), base-uri (3 pts), and frame-ancestors (2 pts).
- X-Frame-Options & X-Content-Type-Options: Prevent clickjacking and MIME-sniffing attacks. Scored 15 points each for proper DENY/nosniff configuration.
- Referrer-Policy & Permissions-Policy: Control referrer leakage and browser API access. Scored 10 points each for strict configurations that limit information exposure.
Privacy, Security & Availability
Your privacy is our priority. The Security Headers Grade Calculator processes everything locally in your browser using pure JavaScript. The header configurations you select are never uploaded, stored, logged, or transmitted to any server. This means you can safely evaluate the security configuration of any website, including internal applications, staging environments, or pre-production servers, without any privacy concerns. The tool is completely free, with no signup, no API keys, and no usage limits - available whenever you need it for security audits, configuration testing, or education.
Related Tools
DNS Propagation Checker
Check if DNS changes have propagated by querying multiple global nameservers (Cloudflare, Google, Quad9). Shows propagation status across regions with live results and colour-coded status indicators - free online DNS propagation checker.
Domain Age Checker
Check the age of any domain in years, months, weeks, and days. Enter a domain name to get its creation date, registration timeline, registrar info, and SEO authority estimate based on domain age - all fetched from the official RDAP registry in real time. Free online domain age checker.
Bulk WHOIS Lookup
Check domain registration information for up to 20 domains at once using the RDAP protocol. View registrar, creation date, expiry date, nameservers, and domain status codes in a sortable table - free online bulk WHOIS lookup.
Domain Expiry Checker
Check when any domain expires - enter a domain name to see its expiration date, days remaining, registrar lock status, auto-renew status, and complete WHOIS details. Colour-coded health indicators show whether renewal is urgent. Free online domain expiry checker.