Both tools are free, both check a site right in your browser, and both hand you a letter grade — so they get compared a lot. But they're built for slightly different jobs. Here's an honest look at where each one wins, so you can pick the right one (or use both).
What Security Headers does well
The Security Headers extension (and the long-running securityheaders.com behind it) is focused and excellent at one thing: grading your HTTP response headers. It gives an A+–F header grade, explains each missing or weak header, and provides ready-to-paste snippets for common servers. It's well-established, widely trusted, and — via securityheaders.com — also offers a hosted scanner and an API you can call from a pipeline.
If headers are the only thing you care about, it's a great pick. It does that job cleanly and has years of reputation behind it.
What SurfaceWatch adds
SurfaceWatch checks the same headers — then keeps going. It grades six layers of your site and rolls them into one A–F score:
- Security headers (CSP, clickjacking, and the rest)
- HTTPS & HSTS configuration
- Cookie flags (Secure, HttpOnly, SameSite)
- Email spoofing — SPF & DMARC
- Outdated JavaScript libraries
- Exposed subdomains from public certificate logs
Every fixable issue comes with a copy-paste fix for nginx, Apache, Netlify, Vercel, Express or your DNS, and Pro adds a watchlist (25 sites with alerts), bulk checks, and branded PDF reports for client work.
Side by side
| Security Headers | SurfaceWatch | |
|---|---|---|
| HTTP security headers | ✓ | ✓ |
| HTTPS / HSTS | partial | ✓ |
| Cookie flags | – | ✓ |
| SPF / DMARC | – | ✓ |
| Outdated JS libraries | – | ✓ |
| Exposed subdomains | – | ✓ |
| One combined site grade | headers only | whole site |
| Hosted scanner + API | ✓ (securityheaders.com) | – |
| Client reports / monitoring | – | ✓ (Pro) |
Where Security Headers is the better fit
Being honest: if you specifically want a headers-only grade, or you need a hosted scanner and an API to wire into CI, Security Headers / securityheaders.com is more established for exactly that. It's also been around far longer, so it has the reputation and the integrations.
Where SurfaceWatch is the better fit
- You want your whole security posture in one grade, not just headers.
- You care about cookies, email spoofing, old libraries or exposed subdomains — things a header checker doesn't look at.
- You're a freelancer or agency auditing client sites and want branded reports and monitoring.
The honest bottom line
Headers only? Security Headers is a clean, trusted choice. Whole-site posture with the exact fixes, in one grade? That's what SurfaceWatch is for. They're not really rivals — one is a focused tool, the other a broader one — and plenty of people run both.
Whichever you use: everything except Content-Security-Policy is safe to paste as-is. For CSP, ship it in report-only mode first and tune it, or you'll break your own scripts.