SurfaceWatch
← All articles
COMPARISON·October 2026·6 min read

Looking for a "Security Headers" extension alternative? Check your whole site, not just headers

If you've used the popular Security Headers extension (or securityheaders.com), you already know the value: open a page, get a grade, see which HTTP response headers are missing. It's a great, focused tool — and if all you ever need is a header check, it does that job well.

But here's the catch most people miss: your HTTP headers are only one slice of what an attacker sees. A site can score an A on headers and still be wide open somewhere else. So if you're looking for an alternative, the real question isn't "which tool grades headers best" — it's "what else am I not checking?"

The five things a header-only checker misses

Headers are one of six layers worth grading. The other five:

  1. HTTPS & HSTS configuration. Not just "is there a padlock," but whether HTTP properly redirects to HTTPS and whether HSTS is set so browsers refuse to downgrade. A missing redirect is a real man-in-the-middle opening.
  2. Cookie flags. A session cookie without HttpOnly can be read by any injected JavaScript; without Secure it can leak over HTTP; without SameSite it's exposed to CSRF. Header checkers don't inspect your cookies.
  3. Email spoofing (SPF & DMARC). If your domain's DNS is missing SPF and DMARC, anyone can send email that looks like it came from you — a classic phishing vector that has nothing to do with your web headers.
  4. Outdated JavaScript libraries. A front-end still shipping jQuery 1.x or an old framework with known CVEs is exploitable no matter how perfect your CSP is.
  5. Exposed subdomains. Public certificate logs reveal the subdomains you've issued certs for — and often that list includes admin., dev., staging. or jenkins. systems you never meant to expose. Attackers check these first.

The alternative: grade all six in one click

This is exactly the gap SurfaceWatch was built for. It's a free Chrome extension that checks the same headers a header-only tool does — plus all five layers above — and rolls them into a single A–F grade for the page you're on. Every issue is listed by severity, and every fixable one comes with a copy-paste fix for nginx, Apache, Netlify, Vercel, Express or your DNS.

So instead of "your headers are a B," you get "your site is a 44/100, here's the ranked list, here's the exact config to fix each one."

When each one is the right choice

Both are free, and the checks are passive (they only read what's already public), so you can run either on sites you don't own. If you've outgrown "headers only," that's your sign to grade the rest.

One honest caveat on the fixes: everything except Content-Security-Policy is safe to paste as-is. For CSP, ship it in report-only mode first and tune it — a strict policy can break your own scripts. A good checker flags this for you.
Grade your whole site — add SurfaceWatch free