Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mozilla’s HTTP Observatory is a free tool for checking selected website security practices, especially HTTP headers. It returns a score and grade with explanations and links to remediation guidance, but it is not a full security audit or proof that a site is safe. First released publicly in 2016, the service moved to MDN in 2024.

What is Mozilla’s HTTP Observatory?

The HTTP Observatory is a web-based checker that evaluates a website against a set of web security best practices. Mozilla security engineer April King first created it as an internal tool for Mozilla websites; Mozilla later made it public to help developers identify configurations that could be improved. MDN now hosts the service and its documentation.

After a scan, the Observatory reports an overall score and grade, explains the checks, and links to guidance for addressing findings. The checks and accompanying documentation have been updated as security standards and practices have evolved.

What does the Observatory check?

MDN describes the current checks as covering selected HTTP headers and related controls, including:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Content Security Policy (CSP): controls browser behavior for resources a page may load.
  • Strict-Transport-Security (HSTS) and HTTPS redirection: encourage or require secure connections.
  • Cookie configuration: checks security-related settings on cookies.
  • Cross-Origin Resource Sharing (CORS): controls which origins may access certain resources.
  • Referrer-Policy: governs referrer information sent with requests.
  • Subresource Integrity (SRI): lets browsers verify that fetched resources match an expected hash.
  • X-Content-Type-Options: helps prevent browsers from interpreting content as a different MIME type.
  • Framing protections: evaluated through CSP frame-ancestors or X-Frame-Options.
  • Cross-Origin-Resource-Policy: sets rules for cross-origin requests involving a resource.

These checks focus on configuration visible to the tool. A passing result does not establish that application code, hosting, access controls, or operational practices are secure.

How to use a result

Use the score and grade as a way to prioritize the specific findings the Observatory identifies, then follow its linked documentation to understand the setting and its trade-offs before changing production behavior. A stricter policy can improve protection but may also disrupt legitimate site functionality if configured incorrectly.

An A+ is not a guarantee of security. MDN cautions that the Observatory cannot programmatically determine the risk level of each site or test every security consideration. It does not, by itself, assess broader architecture, application logic, or operational controls, and its grade is limited to the tool’s defined rules.

The tool is designed for websites. MDN says it can be used with APIs, but results may not accurately represent an API’s security posture; do not treat an API grade as a complete API assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the historical numbers do—and do not—show

MDN reported on July 2, 2024, that the Observatory had scanned more than 6.9 million websites across 47 million scans. These are figures reported for 2024, not a current total.

At launch, SecurityWeek reported on August 26, 2016, that Mozilla figures showed more than 1.3 million websites scanned; over 90 percent did not use all the security technologies checked, about 30 percent used HTTPS, and fewer than 7 percent used the other tested measures. Those figures describe the launch-era sample and should not be read as present-day adoption rates.

What if you find old command-line instructions?

Mozilla’s observatory-cli repository is marked deprecated and directs users to the replacement that backs the MDN HTTP Observatory service. The archived repository describes scanning, exporting reports, rescanning, and applying score or grade thresholds in continuous integration, but its deprecation notice means it should not be presented as the current recommended command-line workflow.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When a broader security assessment is needed

The Observatory can be a useful configuration check, but it answers a narrower question than a security review. When deciding whether you need a broader assessment, consider whether it will examine application logic and architecture, authenticated areas, operational controls, validate findings, and provide remediation support. Those are useful criteria for evaluating an assessment; they are not capabilities established for the Observatory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.