← All projects
Security & networking · Python
HS
headerscan
HTTP security header grader — paste response headers, get an A–F grade and the exact fix for every finding. No network needed.
Grade a response
Result
F
20/100http://127.0.0.1:8011 (HTTP 200)
Scoring
Score starts at 100 and subtracts per finding:
| Severity | Penalty |
|---|---|
| high | −20 |
| medium | −10 |
| low | −5 |
| info | 0 |
Grades: A ≥ 90, B ≥ 80, C ≥ 65, D ≥ 50, else F.
What it checks
- HTTPS in use · HSTS (max-age ≥ 180 days)
- CSP: present, no bare
unsafe-inline, no wildcard script hosts X-Content-Type-Options: nosniff- Clickjacking: XFO or CSP
frame-ancestors - Referrer-Policy, Permissions-Policy
- Version numbers in Server / X-Powered-By
- Cookies: Secure, HttpOnly, SameSite
The CLI sends one GET per URL — only scan sites you own or have permission to test.