We read only what a site sends to every visitor who opens its home page. No login, no form filling, no scanning of hidden paths. Anyone can repeat these checks with their browser’s developer tools.
We look for five response headers that browsers use to protect visitors. The grade counts how many are present: 5 = A, 4 = B, 3 = C, 2 = D, 1 = E, 0 = F. A site that is not served over HTTPS is F regardless.
| Header | What it does |
|---|---|
| strict-transport-security | Forces HTTPS on return visits |
| content-security-policy | Limits which scripts may run |
| x-frame-options | Stops the page being framed (clickjacking) (a CSP frame-ancestors rule counts too) |
| x-content-type-options | Browser must trust the declared type |
| referrer-policy | Controls what leaks in the Referer header |
First response time, home page weight, third-party script hosts and known trackers by name (Google Analytics, Meta Pixel, Hotjar and others). For open-source products, the license comes from the GitHub repository itself. Speed depends on where it is measured from; we say so next to the number.
The owner proves control of the site with one meta tag or a small file. Then a person on our team looks at the listing. Copies, fake products and pages that only exist to collect links are refused.
The featured row is part of a deskkit Audit Premium or Max subscription. Payment decides the position in that row; it never changes a grade or a measurement. Links from featured listings are marked as sponsored.
A grade is about headers, not about whether a product is good or safe to use. A missing header is not proof of a vulnerability, and a full set is not proof of safety.