Skip to content

Compare

SiteRune vs SecurityHeaders.com and Mozilla Observatory

· Configuration notes, not a newsroom.

Those tools grade response headers. SiteRune grades headers too — then robots, schema, interior pages, and a CMS playbook. A+ headers and a banned GPTBot can both be true.

Headers are one chapter

Observatory and securityheaders.com are the right sanity check after you paste CSP. SiteRune's security chapter covers the same public headers plus cookie flags, mixed content, and version banners. We still will not fuzz or weaponize anything.

Then the rest of the brief

An A+ Observatory grade does not tell you /docs is noindex or that llms.txt 404s. Use them to confirm the header snippet. Use SiteRune for the sequenced punch list. We draft nginx / next.config / mu-plugin — they show a letter grade.

Run it on a live URL

The brief will name your CMS and attach the files. Three guest scans, no card.

https://