All integrations
Mozilla HTTP Observatory logo

Mozilla HTTP Observatory

Compliance & SecurityMonitoring

Scan any website's HTTP security with Mozilla's HTTP Observatory, the scanner behind MDN's security report. Point it at a hostname and get a grade from A+ to F and a score out of 145, then the test-by-test detail behind it: Content Security Policy, HSTS, cookies, CORS, clickjacking protection, referrer policy, subresource integrity and the cross-origin isolation headers, each with what the scanner found and what to change. Read the response headers a site sends and the security ones it is missing, follow a site's grade over time to catch a regression, rank several sites against each other, look up the scoring rules themselves, and fail a release when a site drops below the grade you require. No account or API key is required.

12 actions

Actions

Steps your workflow can run in Mozilla HTTP Observatory.

Scan a websiteScan a website's HTTP security and get its grade and score: A+ down to F, out of 145, plus how many of the tests it passed. The quick check, for a status board or a summary line.
Get scan resultsGet a website's full report: the grade and score, every security test with what was found and what to change, the response headers the scanner saw, and the site's past scans. Uses the stored scan while it is under a day old.
Rescan a websiteScan a website again right now and get the full report rather than the stored result, the step to run straight after a deploy that changed headers. A host can be rescanned once a minute.
Get one security testCheck one security control: is HSTS still set, did the Content Security Policy survive the release, and get a plain pass or fail to branch on, with what the scanner found and what to change.
List security testsList a website's security tests, filtered to just the ones that failed, just the ones that passed, or all of them, ordered with the most punishing failure first. The list to paste into a ticket or post to a channel.
Get response headersGet the HTTP response headers a website sent the scanner, either all of them or just the security headers you pick, and, importantly, which of those it is not sending at all. Read off the stored scan, so the site is not fetched again.
Get scan historyGet a website's past scans, newest first, and whether its grade has improved or slipped over that period. The Observatory keeps every scan of every host it has been asked about, so this is where a regression shows up.
Check a website meets a gradeTest a website against a minimum grade, a minimum score, or both, and get a plain pass or fail to branch on, for a release check or a scheduled audit that should raise an alert when a site slips. Comes back with the failing tests and what to change, so the alert can say why.
Compare websitesScan several websites and rank them best-graded first, your own properties side by side, or your site against a competitor's. A host that cannot be scanned is reported without losing the others.
Get the grade distributionGet how every website the Observatory has ever scanned graded, with each grade's share of the web and the share that did at least as well. The context a grade needs: a C is a different story once you know how much of the web scores below it.
Get the scoring referenceGet the Observatory's scoring rules: every test it runs, every outcome each one can reach, what that outcome is worth in points, and MDN's advice for it. Look up what a failure would cost before anyone changes anything, or publish the rules alongside a report.
Get the scanner versionGet the version of the scanner that is answering. Worth storing next to a saved result: the scoring rules change between versions, so a grade is only comparable with another from the same one.

Connect in a few clicks

Authenticate once and every action and trigger for the app is ready to drop into a workflow. No glue code, no maintenance.

Automate across your stack

Chain apps together with triggers, actions, and logic that move data between your tools automatically, so work happens without you.

Secure by default

Credentials are encrypted and scoped per workspace. Connect the tools your team already trusts with confidence.

Automate Mozilla HTTP Observatory with Lodol.

Connect Mozilla HTTP Observatory and build your first workflow in minutes. No credit card required.

Free plan available · No credit card required