Why security headers matter
Missing headers leave common gaps: no CSP makes XSS easier, no HSTS allows downgrade attacks, no X-Frame-Options invites clickjacking. PageGauge scores your coverage and tells you exactly which headers to add.
Certificate health
The report shows your TLS certificate's issuer and days until expiry, and flags a certificate that's invalid or expiring soon — before it takes your site down.
Frequently asked
- Does this replace a full pen test?
- No — it's a fast first-pass check of headers and TLS. Use a dedicated security review for anything sensitive.
- What headers should every site have?
- At minimum HSTS, X-Content-Type-Options: nosniff, a Referrer-Policy, and ideally a Content-Security-Policy.