Free scan and the report grade

The free scan is a public HTTP look at a hostname. No signup, no agent on the server. The grade is what that request could see. It is not a penetration test and it does not prove a site is patched.

What it checks

The score starts at 100 and subtracts for what is missing or exposed:

  • No WAF or CDN detected: 30 points.
  • No working HTTPS: 25 points. An expired certificate: 25. A certificate expiring in under 21 days: 10. An old TLS version (TLS 1.0 or 1.1): 8.
  • Missing HSTS: 12. Missing Content-Security-Policy: 12. Missing X-Frame-Options: 8. Missing X-Content-Type-Options: 6. Missing Referrer-Policy: 4. Missing Permissions-Policy: 3.
  • A Server header that includes a version number: 6.
  • A header that looks like an end-of-life Apache, PHP, or nginx build: 10. One such finding, not a stack of them.

The score is clamped between 0 and 100. Stripping a Server header at the edge can clear the leak finding. It does not patch the origin.

The grade

Grade bands
GradeScoreHeadline
A90–100Strong posture. A shield is in front and the important headers are present.
B80–89Solid, with a few gaps. Usually lower-weight headers or a minor leak.
C70–79Mixed. Often no shield, or several high-value headers are absent.
D55–69Weak. The origin is likely exposed, or several high-impact headers are missing.
F0–54Exposed. No shield and/or multiple high-impact gaps.

Those cuts match the grader: 100 is an A (A), 89 is a B (B), 79 is a C (C), 69 is a D (D), and 54 is an F (F). A host that could not be scanned is not given one of these letters.

You can opt in to an email of the grade. The scan page does not require it. The report URL is public for hosts we will index. Reports for the operator’s own sites are not indexed.

Related guides

More in this section