Web status · Web status & headers

Security headers: the A-F grade explained

Published 2026-10-05

A security headers grade (A, B, C, D, E, F) summarizes how well your site is configured to resist the most common browser-level attacks: clickjacking, XSS, mixed content, downgrade attacks. Each missing or misconfigured header costs you. The grader gives a 0–100 score and a checklist of what to add.

TL;DR

A security headers grader checks your site for HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, and 5 others. Here is what each one does and how to fix it.

The four headers that matter most

Strict-Transport-Security (HSTS) tells browsers to use HTTPS only for the next year. Content-Security-Policy (CSP) restricts what scripts and styles the page can load. X-Frame-Options or frame-ancestors in CSP prevents the page from being embedded in an iframe. Referrer-Policy controls how much information about the previous URL is sent. Together, these four cover the most common attack vectors.

The smaller ones

X-Content-Type-Options: nosniff prevents MIME-sniffing (where a browser guesses the content type and executes it as a different type). Permissions-Policy disables browser features by default (camera, microphone, geolocation). Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy are newer headers for isolation. Cross-Origin-Resource-Policy controls which sites can load your resources.

How to get from F to A

Most sites can reach A in 30 minutes by adding the four headers above. HSTS is one line: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. CSP starts permissive (default-src 'self') and tightens over time. X-Frame-Options is one line: DENY (or SAMEORIGIN if you use iframes). The grader tells you which ones are missing and gives you the exact header to add.

Common gotchas

HSTS only works over HTTPS — adding it on an HTTP site has no effect. CSP conflicts with inline scripts (you need nonces or hashes, or you can use strict-dynamic). Permissions-Policy has a default-allow and default-deny mode — choose one. X-Frame-Options is being replaced by frame-ancestors in CSP, but still works for legacy browsers. The grader scores each header individually, so a partial config still gets partial credit.

Try it →

Run the Security headers tool on sitetrace.it.com — paste a value and get an instant answer.

Open Security headers