Skip to content
Solvex Space

Cybersecurity · free, no signup

Security Header & SSL Grader

Enter a URL to score its HTTP security headers, TLS configuration and cookie flags against best practice, with a plain-English explanation of every gap and how to fix it.

Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.

Fetches one page over the public internet and reports what its response headers actually protect against — including the redirect chain that got there, which is where an HTTPS site can still expose a first request. Any Content-Security-Policy and Set-Cookie headers are analysed by the same engines behind the dedicated CSP and cookie tools. No page content is read and nothing is submitted.

A site you own, manage or are authorized to assess. Private and internal addresses are refused.

What happens to what you enter

  • The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
  • Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
  • An email address is stored only where a tool offers to send you a report and you choose to give one.

Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.

When a free check is not enough

This tool reads what is public and reports what it can see. The Web Application Penetration Testing engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.

Explore Web Application Penetration Testing
Security Header & SSL Grader — Solvex Space