HTTP Security Header & Defense Grader

Audit website response headers, verify HSTS/CSP/X-Frame-Options, and generate production Nginx hardening rules.

Audit response headers to evaluate defense against clickjacking, cross-site scripting (XSS), MIME-sniffing, and server version leakage. Calculates an overall security grade (A+ to F) and outputs copy-ready Nginx, Apache, and Cloudflare configuration snippets.

Features

  • Strict-Transport-Security (HSTS) & CSP compliance
  • X-Frame-Options & Clickjacking defense scoring
  • Server token & information leak detection
  • Production Nginx server hardening code generator

More AI tools