Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchMozilla’s HTTP Observatory is a free tool for checking selected website security practices, especially HTTP headers. It returns a score and grade with explanations and links to remediation guidance, but it is not a full security audit or proof that a site is safe. First released publicly in 2016, the service moved to MDN in 2024.
What is Mozilla’s HTTP Observatory?
The HTTP Observatory is a web-based checker that evaluates a website against a set of web security best practices. Mozilla security engineer April King first created it as an internal tool for Mozilla websites; Mozilla later made it public to help developers identify configurations that could be improved. MDN now hosts the service and its documentation.
After a scan, the Observatory reports an overall score and grade, explains the checks, and links to guidance for addressing findings. The checks and accompanying documentation have been updated as security standards and practices have evolved.
What does the Observatory check?
MDN describes the current checks as covering selected HTTP headers and related controls, including:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Content Security Policy (CSP): controls browser behavior for resources a page may load.
- Strict-Transport-Security (HSTS) and HTTPS redirection: encourage or require secure connections.
- Cookie configuration: checks security-related settings on cookies.
- Cross-Origin Resource Sharing (CORS): controls which origins may access certain resources.
- Referrer-Policy: governs referrer information sent with requests.
- Subresource Integrity (SRI): lets browsers verify that fetched resources match an expected hash.
- X-Content-Type-Options: helps prevent browsers from interpreting content as a different MIME type.
- Framing protections: evaluated through CSP
frame-ancestorsor X-Frame-Options. - Cross-Origin-Resource-Policy: sets rules for cross-origin requests involving a resource.
These checks focus on configuration visible to the tool. A passing result does not establish that application code, hosting, access controls, or operational practices are secure.
How to use a result
Use the score and grade as a way to prioritize the specific findings the Observatory identifies, then follow its linked documentation to understand the setting and its trade-offs before changing production behavior. A stricter policy can improve protection but may also disrupt legitimate site functionality if configured incorrectly.
Rank #2
An A+ is not a guarantee of security. MDN cautions that the Observatory cannot programmatically determine the risk level of each site or test every security consideration. It does not, by itself, assess broader architecture, application logic, or operational controls, and its grade is limited to the tool’s defined rules.
The tool is designed for websites. MDN says it can be used with APIs, but results may not accurately represent an API’s security posture; do not treat an API grade as a complete API assessment.
What the historical numbers do—and do not—show
MDN reported on July 2, 2024, that the Observatory had scanned more than 6.9 million websites across 47 million scans. These are figures reported for 2024, not a current total.
At launch, SecurityWeek reported on August 26, 2016, that Mozilla figures showed more than 1.3 million websites scanned; over 90 percent did not use all the security technologies checked, about 30 percent used HTTPS, and fewer than 7 percent used the other tested measures. Those figures describe the launch-era sample and should not be read as present-day adoption rates.
Rank #4
What if you find old command-line instructions?
Mozilla’s observatory-cli repository is marked deprecated and directs users to the replacement that backs the MDN HTTP Observatory service. The archived repository describes scanning, exporting reports, rescanning, and applying score or grade thresholds in continuous integration, but its deprecation notice means it should not be presented as the current recommended command-line workflow.
When a broader security assessment is needed
The Observatory can be a useful configuration check, but it answers a narrower question than a security review. When deciding whether you need a broader assessment, consider whether it will examine application logic and architecture, authenticated areas, operational controls, validate findings, and provide remediation support. Those are useful criteria for evaluating an assessment; they are not capabilities established for the Observatory.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

