HTTP Security Header & Defense Grader
Audit website response headers, verify HSTS/CSP/X-Frame-Options, and generate production Nginx hardening rules.
Audit response headers to evaluate defense against clickjacking, cross-site scripting (XSS), MIME-sniffing, and server version leakage. Calculates an overall security grade (A+ to F) and outputs copy-ready Nginx, Apache, and Cloudflare configuration snippets.
Features
- Strict-Transport-Security (HSTS) & CSP compliance
- X-Frame-Options & Clickjacking defense scoring
- Server token & information leak detection
- Production Nginx server hardening code generator
More AI tools
- Accessibility Tree Audit & Builder — Map and optimize the accessibility tree that AI agents use to browse your site.
- Profile Link Verifier — Bidirectional rel=me verification — prove your profiles are really yours.
- NAP Consistency Checker — Verify your Name, Address, and Phone match exactly across the web.
- Context Architect — Build the context package your AI actually needs.
- Agent Loop Builder — Turn recurring work into a controlled agent loop.
- Agent Guardrail Designer — Design permissions, approvals, and agent failure boundaries.
- Workflow Debugger — Find why an agent workflow stalls, loops, or fails.
- Viral Clipper — Auto-edit long videos into shorts.