Compare
SiteRune vs SecurityHeaders.com and Mozilla Observatory
· Configuration notes, not a newsroom.
Those tools grade response headers. SiteRune grades headers too — then robots, schema, interior pages, and a CMS playbook. A+ headers and a banned GPTBot can both be true.
SEHeaders are one chapter
Observatory and securityheaders.com are the right sanity check after you paste CSP. SiteRune's security chapter covers the same public headers plus cookie flags, mixed content, and version banners. We still will not fuzz or weaponize anything.
Then the rest of the brief
An A+ Observatory grade does not tell you /docs is noindex or that llms.txt 404s. Use them to confirm the header snippet. Use SiteRune for the sequenced punch list. We draft nginx / next.config / mu-plugin — they show a letter grade.
Capability table
| Capability | SiteRune | SecurityHeaders.com |
|---|---|---|
| Letter-grade for response headers | Scored chapter | Yes |
| Cookie flags / mixed content | Yes | Partial |
| Interior pages / noindex | Yes | No |
| robots / schema / llms.txt | Yes | No |
| CMS playbook + snippets | Yes | No |
| Penetration test | No | No |
FAQ
Does SiteRune replace securityheaders?
No. Use the comparison table. SiteRune is a hosted configuration brief with CMS dialect and ship files. It does not replace rank tracking, backlink graphs, lab Core Web Vitals, or a desktop site-wide crawl.
What does a SiteRune scan actually fetch?
HTML and headers from this vantage point, robots.txt, sitemap, llms.txt, security.txt, and a polite walk of same-origin interiors. No headless Chrome. No exploits.
Run it on a live URL
Same scan engine. Guest scans stay free.