Reports. Decisions. Results.

HTTP Observatory Report

Website security report every week in your inbox.

What is protecting your website, what is missing, and what changed since the last report. Scanned with Mozilla’s HTTP Observatory and written up so anyone on the team can read it. No dashboard to log into.

Free plan: 4 reports a month, no card required. Built using Mozilla’s HTTP Observatory

WebPerformance Report Inbox

Sponsored by

Trusted by teams at Google, Airbnb, Stripe, IKEA, Nestlé and dozens more global brands.

Subscribe

Provide your email address to subscribe. Example: abc@xyz.com

Provide your Domain. Example: example.com

Built using Mozilla’s HTTP Observatory.

Testimonials

I love having a weekly reminder of the Web Performance of my site, as another checkpoint that I’m not letting things regress, Also look forward to the featured links in case I missed anything in the webperf world in the last week.

Barry Pollard,
Web Performance Developer Advocate
at Google

WPR provides an easy way for me to observe and share simplified performance monitoring results with other engineers. Compared to other solutions, WPR just gets to the point with the data you need.

Jacob Gross,
Senior Performance Engineer
at Framer

A snapshot report that provides valuable insights to help you focus on your website’s performance, based on data, makes it a worthwhile choice, especially considering such factors influence SEO.

Madhu Kumar C,
Digital Marketer and AI Blogger
Independent Consultant

About HTTP Observatory

The HTTP Observatory is a tool developed by Mozilla to help website owners understand how well their sites are implementing modern security practices at the HTTP level. It works by analyzing the response headers returned by a server and checking them against a set of best practices widely accepted across the web industry.

By including the HTTP Observatory in the WebPerformance Report, we provide an added layer of insight focused specifically on web security. The report evaluates your site for proper configuration of important headers such as Content Security Policy, Strict-Transport-Security, X-Frame-Options, Referrer Policy, and others. These headers play a vital role in defending your website against threats like clickjacking, code injection, and man-in-the-middle attacks.

Understanding and improving HTTP headers is often overlooked, yet it is essential for maintaining a secure and trustworthy website. With the help of the HTTP Observatory, we not only highlight areas for improvement but also guide you toward simple, actionable changes that can significantly boost your site’s security and compliance with web standards.

Users

We are really proud that our users also come from big companies and big brands around the world and are using Web Performance Report to monitor the web performance of their websites every week from their inboxes. 🎉

Report Catalog

Five reports, one subscription. Pick the ones that matter to your site. Each has its own recipients and schedule.

WebPageTest Report

The gold-standard open-source performance tool. Core Web Vitals, filmstrip, request map.

Get the report

HTTP Observatory Report

Mozilla’s in-depth assessment of your HTTP headers and security configuration.

Get the report

WAVE Report

The accessibility barriers on your pages, checked against standards such as WCAG, ADA and the EU Accessibility Directive.

Get the report

GA4 Report

Your traffic numbers set against the period before, so a channel drying up shows up while you can still act on it.

Get the report

Search Console Report

Impressions, clicks, positions and the queries bringing visitors in from organic search.

Coming soon

Want all five?

Every report type is unlocked on the paid plans, each with its own URLs, recipients and schedule.

See Plans

HTTP Observatory Report

HTTP Observatory Report Details

Scoring. CSP analysis. Cookies. Raw server headers. Scan history.

HTTP Observatory Report Detail
Scan Summary

Scan Summary

Each site tested by Observatory is awarded a grade based on its final score.

Scoring

CSP, Cookies, CORS, Redirections, Referrer Policy, HSTS, SRI, X-Frame-Options

Scoring
CSP Analyst

CSP Analysis

The HTTP Content-Security-Policy response header.

Raw Server Headers

Age, Date, Vary, Server, Connection, Content-Type, X-Powered-By, Cache_Control, Last-Modified.

>Raw server headers

Contact

Get in touch: info@webperformancereport.com

WebPerformance Report - Web page performance test every week in your inbox.  | Product Hunt

WebPerformance Report
Reports. Decisions. Results.
(stable version 😊)