HTTPS & HSTS
The page should be served over HTTPS, plain HTTP should redirect to it, and Strict-Transport-Security should tell browsers to never use HTTP again (max-age, includeSubDomains, preload).
Free one-off scan of HSTS, Content-Security-Policy, framing, MIME sniffing, Referrer-Policy, Permissions-Policy, cross-origin isolation and cookie flags. You get a 0–100 score, an A+ to F grade, and copy-paste fixes. No sign-up.
Examples: github.com · cloudflare.com · example.com
The page should be served over HTTPS, plain HTTP should redirect to it, and Strict-Transport-Security should tell browsers to never use HTTP again (max-age, includeSubDomains, preload).
We parse every directive and flag 'unsafe-inline', 'unsafe-eval', wildcard sources and missing default-src, object-src, base-uri and frame-ancestors. Report-Only policies are recognized but not counted as protection.
X-Frame-Options (or CSP frame-ancestors) stops other sites from framing your page. X-Content-Type-Options: nosniff stops browsers from guessing content types.
Referrer-Policy controls how much of your URLs leak to other sites. Permissions-Policy turns off features like camera, microphone and geolocation that you don't use.
Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy protect against cross-site leaks. Cross-Origin-Embedder-Policy is reported for information only.
Cookie flags (Secure, HttpOnly, SameSite), the deprecated X-XSS-Protection, and headers that leak software versions (Server, X-Powered-By, X-AspNet-Version).
Scoring: HTTPS 10 · HSTS 15 · CSP 25 · Framing 10 · nosniff 10 · Referrer-Policy 10 · Permissions-Policy 5 · COOP 5 · CORP 5 · Cookies 5 = 100, minus up to 5 for version leaks. A+ ≥ 95, A ≥ 85, B ≥ 70, C ≥ 55, D ≥ 40, otherwise F. Sites without HTTPS are capped at 39 (F). Full scoring table.
No key needed, CORS enabled. Requests are rate-limited per IP (about 30 scans/min) and results are cached in memory for 2 minutes.
curl "https://headerguard.mike-tusa.workers.dev/api/scan?url=example.com"
Embeddable grade badge: /badge/<host>.svg — see the report page after a scan, or the docs.
API reference and response format · For AI agents (MCP server, llms.txt, OpenAPI)
For developers and CI: about 120 scans/min per license key (vs about 30/min per IP on the free plan), plus POST /api/scan/batch (up to 5 URLs). Same grading, same SSRF protections, same per-request CPU cap. Free badge and one-off scans stay free.
Get HeaderGuard Pro · API & key usage
Paid via Polar (merchant of record). Cancel anytime in the Polar customer portal. Support: digitalpromohub.support@gmail.com.
HeaderGuard is also a remote Model Context Protocol (MCP) server. Most MCP clients accept this config; some use a different format (for example, VS Code uses a servers key). Clients with a settings screen just need the URL https://headerguard.mike-tusa.workers.dev/mcp.
{ "mcpServers": { "headerguard": { "type": "http", "url": "https://headerguard.mike-tusa.workers.dev/mcp" } } }
One read-only tool, scan_headers (a URL or domain in, the same score, grade, findings and fixes as the JSON API out). Same limits and the same HeaderGuard Pro license key as the API: send it as Authorization: Bearer HDRG-… for higher limits. No key is needed.
Machine-readable docs: llms.txt · OpenAPI 3.1 spec
We don't store the URLs you scan or the results. A scan result is kept only in the server's memory for up to 2 minutes, so repeat requests are fast, and then it is discarded. The embeddable grade badge (/badge/<host>.svg) may keep a host's grade letter at the edge for up to about 24 hours (see badge docs); that cache holds only the SVG badge, not the URL list or raw headers. We don't keep request logs, and your IP address is used only in short-lived counters for rate limiting. If you send a HeaderGuard Pro license key, we check it against our license store (a short-lived edge cache of the result); we do not log the key. Payment details are handled by Polar as merchant of record, not by us. The site runs on Cloudflare Workers, and Cloudflare processes requests in order to serve it.
To run a scan, our server sends ordinary GET requests to the site you entered (plus a check of its plain-HTTP address) and reads only the response headers; the page content is discarded unread. Before each request it looks up the site's IP addresses via DNS-over-HTTPS (Cloudflare cloudflare-dns.com, with Google dns.google as fallback), so those resolvers see the hostname. Cookie values set by the scanned site are never shown or kept.
No analytics, no cookies, no third-party scripts or resources on this site.
Contact: digitalpromohub.support@gmail.com