September 2026
A security grade from A to F, and the detail behind it
August’s audit showed it: a finding without a hierarchy helps nobody. The report now returns a score out of a hundred, its letter, and for every point lost the exact line to add to the server.
Why a grade
A list of six missing headers does not say which ones matter. The reader walks away with an inventory and no order of priority, which amounts to saying nothing. The grade starts at a hundred and subtracts. HSTS and Content-Security-Policy are worth eighteen points each, because they are the only two that close an entire class of attack: falling back to cleartext for the first, content injection for the second. X-Content-Type-Options and X-Frame-Options are worth eight, Referrer-Policy and Permissions-Policy six. Those harden, they do not protect on their own.
Without HTTPS, F, no discussion
When the page is not served over HTTPS, the grade drops to F and the detail is not computed. That is not display severity, it is the only honest reading: everything travels in cleartext, any intermediary reads and rewrites the page, and no header changes that. Adding hardening points on top of an open connection would produce a flattering, false grade.
What costs points beyond headers
- An already expired certificate costs forty points, a certificate that does not match the site name costs thirty.
- Fifteen days or less before expiry: fifteen points. Thirty days or less: only five, because automatic renewal fires inside that window, as August’s audit showed.
- A single cookie set without Secure or without HttpOnly: eight points.
- A Server header showing a version number, or an X-Powered-By: four points. That is not a vulnerability, it is a hint handed to whoever is looking for a vulnerable version.
- No SPF, no DMARC: five points each. A domain without DMARC can be impersonated in email, even if it receives no mail at all.
- A domain name expiring in less than thirty days: eight points, and fifteen if it has already lapsed.
Naming a header is not enough
“You are missing Permissions-Policy” means nothing to someone who does not administer a server. They leave without knowing whether to worry, or what to ask their host for. Every missing header therefore comes with three things: what it protects, what an attacker gains without it, and the line to copy as is. For HSTS that line is “Strict-Transport-Security: max-age=31536000; includeSubDomains”. These are the values our own API applies to its responses, with one exception: the content policy of an API that only serves JSON is too strict for a site loading its images and scripts, so we suggest a value fit for a website.
The same grade, continuously
The public audit and continuous monitoring share a single scoring function. The audit brings what it measures on top — the certificate, the domain’s DNS — while monitoring sticks to the headers of each response. The useful consequence: a monitored site’s grade is recomputed on every pass, and a drop shows up. A B that turns into a D is a release that removed a content policy. Nobody will tell you, the page still renders.
What the grade does not say
It measures presence, not tuning. A permissive content policy counts as present, and an A grade does not mean a site is safe: it means it has not forgotten the protections everyone forgets. The audit does not replace an application review, it reports what is missing and what regresses. That is little, it is measurable, and it is exactly what no team watches spontaneously.