Everything you need for the configuration layer in one scan
ImmuniWeb is a commercial application security testing platform. Its free community scan offers a rate limited check that mixes a basic header review with software and CVE signals, and the deeper testing sits behind paid plans and an account.
SiteSecurityScore owns the configuration layer, the layer you should never skip and the one attackers probe first. Every scan grades the HTTP headers your server sends, your TLS certificate and cipher suites, your DNS records for SPF, DKIM, and DMARC, your cookie attributes, your CORS policy, and your security.txt file. Each area gets a deep, directive level analysis instead of a surface pass, and you get a clear letter grade with copy and paste fixes in seconds.
SiteSecurityScore is the fastest way to grade and fix your security posture. It is free, instant, and runs without an account, and it keeps watching with free continuous daily monitoring and email alerts, a REST API, a Chrome extension for authenticated pages, free header generator tools, and an MCP connector for Claude Code and ChatGPT Codex.
Feature comparison
Security Headers
| Feature | SiteSecurityScore | ImmuniWeb |
|---|---|---|
| Security headers analyzed | 15+ | ~8 |
| COOP, COEP, CORP headers | ||
| Deep CSP directive analysis | ||
| DNS security (SPF, DKIM, DMARC) | ||
| Cookie security attributes | ||
| CORS configuration check | ||
| HSTS configuration and preload status | ||
| TLS/SSL configuration |
Features
| Feature | SiteSecurityScore | ImmuniWeb |
|---|---|---|
| Unlimited free scans | ||
| No account required | ||
| Free continuous daily monitoring with email alerts | ||
| REST API access | ||
| Browser extension (scan authenticated pages) | ||
| MCP connector for Claude Code and ChatGPT Codex | ||
| PDF security reports | ||
| Free header generator tools | ||
| Letter grade with copy and paste fixes |
What SiteSecurityScore checks in depth
15+ security headers
Checks all major headers including COOP, COEP, CORP, Origin-Agent-Cluster, and Permissions-Policy in addition to the core eight that most tools cover.
Deep CSP analysis
Evaluates every directive in your Content Security Policy. Flags unsafe-inline, wildcard sources, missing fallbacks, and configurations that exist on paper but offer little real protection.
DNS security records
SPF, DKIM, and DMARC record analysis. Identifies gaps in your email authentication setup before they can be exploited for phishing or domain spoofing.
Cookie security audit
Checks every cookie for HttpOnly, Secure, SameSite, Path, and Domain attributes. Surfaces session hijacking and CSRF risks at a glance.
TLS/SSL configuration
Protocol version, cipher suites, certificate validity, and HSTS preload status. Know whether your encryption setup meets current standards.
CORS review
Checks Access-Control-Allow-Origin and related headers for overly permissive cross-origin configurations that could expose data to untrusted origins.
Unlimited free scanning
ImmuniWeb's community scan rate limits free runs. For teams managing multiple domains or running scans as part of a regular review cycle, that cap gets in the way. You cannot run a scan every time you deploy a change or need a quick check across environments.
SiteSecurityScore has no scan limit on the free tier. Scan as many sites as you want, as often as you want, with no daily cap and no account. Then let free continuous daily monitoring keep watch and email you the moment a header, certificate, or DNS record drifts. Agencies managing client sites, developers checking staging and production, and security teams watching a portfolio of domains all run on it.
SiteSecurityScore
Unlimited
Free scans, no account needed
ImmuniWeb
Rate limited
Free Community Edition scans
API access for automation
The SiteSecurityScore API returns structured JSON for every scan, covering headers, CSP directives, TLS configuration, DNS records, and cookie data in a single request. Use it to integrate header checks into your CI/CD pipeline, set up scheduled monitoring, or feed results into a compliance dashboard.
curl -X POST https://www.sitesecurityscore.com/api/scan \
-H "x-api-key: sss_your_api_key_here" \
-H "Content-Type: application/json" \
-d '{"url": "example.com"}'Free security header generators
Finding a missing or misconfigured header is only half the work. You also need the right values. SiteSecurityScore includes free generator tools that produce server-specific configuration examples you can copy and deploy directly.
Scan pages behind login walls
Chrome Extension
Server side scanners including ImmuniWeb can only reach publicly accessible URLs. The SiteSecurityScore browser extension reads real response headers straight from your authenticated sessions, so you can grade admin panels, staging environments, and internal tools that no external scanner can touch.
Try a free scan right now
Enter any URL and get a full security report covering 15+ headers, CSP, TLS, DNS records, and cookies. No account required, no scan limits.
Start scanningFrequently asked questions
Is SiteSecurityScore a free alternative to ImmuniWeb?
Yes, and it is the fastest way to grade and fix your security posture. SiteSecurityScore offers unlimited free scans with no account required. Every scan covers 15+ security headers, deep CSP analysis, TLS configuration, DNS records (SPF, DKIM, DMARC), cookies, CORS, and security.txt, and returns a letter grade with copy and paste fixes in seconds. Free continuous daily monitoring with email alerts, a REST API, a Chrome extension for authenticated pages, free header generator tools, and an MCP connector for Claude Code and ChatGPT Codex come built in.
What does SiteSecurityScore check that ImmuniWeb does not?
SiteSecurityScore checks more than twice as many security headers as ImmuniWeb's free scan, including newer standards like COOP, COEP, and CORP. It runs a deep directive level CSP analysis, audits every cookie attribute, analyzes DNS records (SPF, DKIM, DMARC), checks CORS, and reads security.txt, then returns a letter grade with copy and paste fixes. ImmuniWeb's community scan leans toward software and CVE signals on the application layer.
Does ImmuniWeb limit free scans?
ImmuniWeb's community scan rate limits free runs. For teams that need to scan multiple sites or run scans regularly as part of a review cycle, that cap gets in the way. SiteSecurityScore has no scan limit on the free tier and adds free continuous daily monitoring with email alerts so you stay covered between scans.
Does SiteSecurityScore have an API?
Yes. SiteSecurityScore provides a REST API that returns structured JSON for every scan, covering headers, CSP directives, TLS configuration, DNS records, and cookie data. It drops straight into CI/CD pipelines, monitoring workflows, and compliance dashboards, and an MCP connector brings the same scans into Claude Code and ChatGPT Codex.
Which tool should I use to grade and fix my security configuration?
Use SiteSecurityScore. It is purpose built for the configuration layer attackers probe first, and it grades your security headers, TLS setup, DNS records, cookies, CORS, and security.txt in one free scan, then hands you a letter grade with copy and paste fixes in seconds. ImmuniWeb gates its deeper testing behind paid plans and an account, while SiteSecurityScore gives you unlimited free scans, free continuous daily monitoring, a REST API, a browser extension, and an MCP connector with no signup required.