Powered by Mozilla HTTP Observatory

Your security headers were correct. Were they correct after the last deploy?

PingView scans your site with the same Mozilla HTTP Observatory engine that powers MDN's scanner, on a schedule, and tells you when a header changes or disappears.

No credit card
Official MDN engine
Grade + per-test detail
HTTP ObservatoryB+ · 75
  • Content-Security-Policypass
  • Strict-Transport-Securitypass
  • X-Content-Type-Optionspass
  • Referrer-Policyreview

A one-off scan protects you for exactly one day

Headers get removed by accident

A proxy config change, a new CDN rule or a framework upgrade silently drops your Content-Security-Policy. Nothing errors, nothing goes down, the page still returns 200.

You lose a protection you already paid an engineer to add.

Presence is not configuration

A header that exists can still be wrong. A CSP with unsafe-inline, an HSTS without a meaningful max-age, or a permissive CORS policy all pass a naive header check.

You believe you are covered while the policy does nothing.

No record when the client asks

Security questionnaires and vendor reviews want evidence over time, not a scan you ran the morning they asked.

Every audit turns into a scramble.

The MDN scanner, running continuously

Same engine, same grading, attached to a monitor you already have.

Official Mozilla engine

Scans run through the @mdn/mdn-http-observatory package, so your grade and score match what the public MDN scanner would report.

Configuration, not just presence

Each test is evaluated for correct configuration and current best practice, with the reason and recommendation stored alongside the result.

Redirect chain included

The scan checks both the HTTP redirect behaviour and the HTTPS response, regardless of the scheme configured on the monitor, so a misconfigured redirect cannot hide.

TLS configuration graded too

Alongside headers, PingView grades your TLS setup from A+ to F, penalising expired certificates, deprecated protocols and weak cipher suites.

Why teams monitor headers with PingView

Header posture sits on the same monitor as uptime, SSL expiry and Lighthouse, not in a separate security tool

Failed scans are stored with diagnostic detail instead of vanishing, so you can tell a broken scan from a bad grade

Findings feed the branded PDF and the weekly report your client already receives

100+
Verified Users
500+
Global Monitors
4
Global Regions
99.99%
Uptime
🇵🇱POLISH COMPANY
🛡️GDPR COMPLIANT
📄VAT INVOICES

Simple, predictable pricing

Professional

PLN 75/month
  • 100 monitors
  • 30-second intervals
  • Advanced security
  • Teams support
Start monitoring free

Security header monitoring questions

Is this the real Mozilla HTTP Observatory?

Yes. PingView runs the official @mdn/mdn-http-observatory package, the same engine behind MDN's public scanner. Grade, score and individual test results come from it directly.

Which security headers are checked?

The Observatory test suite covers Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Subresource Integrity, cookie flags, CORS policy and redirect behaviour, each graded on configuration rather than presence alone.

How often are scans run?

Scans run automatically on a recurring schedule with a minimum interval of 24 hours per monitor, so you see posture change over time rather than a single reading.

What happens if a scan fails?

Failed attempts are persisted with diagnostic details and linked to the monitor, so a scan that could not complete is visibly different from a site that genuinely scored badly.

Is this the same as SSL monitoring?

They are related but distinct. SSL monitoring watches certificate expiry and alerts before it lapses. Security header scanning grades how your application instructs the browser to behave. PingView runs both, and the TLS configuration grade bridges them.

Which plan includes security header scanning?

Security header scanning via HTTP Observatory is part of the Professional plan, together with TLS scanning, dependency scanning, Lighthouse audits and reputation risk checks.

Find out when a header disappears. Not during the next audit.

Put the Mozilla HTTP Observatory scanner on a schedule and keep the evidence.

30 days free
✓ No credit card
✓ Cancel anytime