deskkit Launches

How we measure

We read only what a site sends to every visitor who opens its home page. No login, no form filling, no scanning of hidden paths. Anyone can repeat these checks with their browser’s developer tools.

Security headers grade

We look for five response headers that browsers use to protect visitors. The grade counts how many are present: 5 = A, 4 = B, 3 = C, 2 = D, 1 = E, 0 = F. A site that is not served over HTTPS is F regardless.

HeaderWhat it does
strict-transport-securityForces HTTPS on return visits
content-security-policyLimits which scripts may run
x-frame-optionsStops the page being framed (clickjacking) (a CSP frame-ancestors rule counts too)
x-content-type-optionsBrowser must trust the declared type
referrer-policyControls what leaks in the Referer header

Information we show but do not grade

First response time, home page weight, third-party script hosts and known trackers by name (Google Analytics, Meta Pixel, Hotjar and others). For open-source products, the license comes from the GitHub repository itself. Speed depends on where it is measured from; we say so next to the number.

Before anything is listed

The owner proves control of the site with one meta tag or a small file. Then a person on our team looks at the listing. Copies, fake products and pages that only exist to collect links are refused.

Featured places

The featured row is part of a deskkit Audit Premium or Max subscription. Payment decides the position in that row; it never changes a grade or a measurement. Links from featured listings are marked as sponsored.

Limits

A grade is about headers, not about whether a product is good or safe to use. A missing header is not proof of a vulnerability, and a full set is not proof of safety.