VPNSmith
self-host-vpnINFO

Security Headers of 99 VPN and Privacy Websites, Measured (August 2026)

We scanned the homepages of 99 VPN providers, password managers, encrypted messengers and privacy tools for HTTP security headers. Three score 100/100; 22 declare none at all. Full table, published method, and the scanner so you can re-run it.

By Eric Gerard · Founder · VPNSmith - Self-host VPN & GDPR VPS specialist18 min readPhoto: Pexels

When a tool's entire pitch is privacy, its own website is the first thing a visitor can actually check. So we checked it - on 99 sites across VPN providers, password managers, encrypted messengers, self-hosted tools and privacy-focused hosts.

What the score is, and what it is not

This is the part to read before the table, because a number without its meaning is worse than no number.

We measure what the web server declares to your browser. Eight headers, on the homepage, on one day. That is the whole scope.

We do not measure the product. A password manager scoring F here may have flawless cryptography; a VPN scoring A+ may still keep logs. The headers say whether someone switched on the browser-side hardening. That is a signal about engineering care, not a verdict on the software.

If you take one thing from this page: a low grade is not an accusation, and a high grade is not a guarantee.

How the score is calculated

Eight headers, weighted by what each actually prevents rather than counted equally:

HeaderPointsWhat it prevents
Content-Security-Policy25script injection - the broadest single defence
Strict-Transport-Security20silent downgrade to plain HTTP
X-Content-Type-Options10MIME sniffing
X-Frame-Options10clickjacking (or frame-ancestors in CSP)
Referrer-Policy10URL leakage to third parties
Permissions-Policy10unrequested camera, microphone, geolocation
Cross-Origin-Opener-Policy10cross-origin window interference
Cross-Origin-Resource-Policy5unwanted cross-origin embedding

Grades: A+ 90-100 · A 75-89 · B 60-74 · C 40-59 · D 20-39 · F under 20.

A site that uses frame-ancestors inside its CSP receives the X-Frame-Options points. Without that rule we would have penalised sites for choosing the more modern option - a flaw in our scoring, not in their configuration.

Seven sites could not be measured (timeout, certificate failure, or an automated client refused). Their rows are empty, not zero. A failed measurement is not a finding.

A black laminated padlock hanging on a black square-grid metal fence, photographed against a pale green-grey sky that fills the squares of the grid.
A black laminated padlock hanging on a black square-grid metal fence, photographed against a pale green-grey sky that fills the squares of the grid.

A padlock on a grid fence, the sky showing through every square. Headers work the same way: each one closes a specific opening, and the ones you leave out stay open regardless of how good the lock is.

The full ranking, August 2026

#SiteGradeScoreCSPHSTSX-CTOXFORefPermsCOOPCORP
1grapheneos.orgA+100
2mullvad.netA+100
3whonix.orgA+100
4cryptpad.frA+90
5bitwarden.comA85
6cryptostorm.isA85
7duckduckgo.comA85
8element.ioA85
9exodus-privacy.eu.orgA85
10netbird.ioA85
11njal.laA85
12posteo.deA85
13startmail.comA85
14vaultwarden.devA85
15windscribe.comA85
16www.dashlane.comA85
17www.passbolt.comA85
181password.comA75
19azirevpn.comA75
20nextcloud.comA75
21privacytools.ioA75
22proton.meA75
23searx.beA75
24standardnotes.comA75
25threema.chA75
26tutanota.comA75
27www.ovpn.comA75
28www.scaleway.comA75
29www.startpage.comA75
30www.torproject.orgA75
31cryptomator.orgB65
32firezone.devB65
33ivpn.netB65
34libreswan.orgB65
35mailbox.orgB65
36tailscale.comB65
37www.lastpass.comB65
38www.privacyguides.orgB65
39www.wire.comB65
40matrix.orgB60
41netfoundry.ioB60
42obsidian.mdB60
43openziti.ioB60
44traefik.ioB60
45www.mojeek.comC55
46airvpn.orgC50
47owncloud.comC50
48protonvpn.comC50
49www.expressvpn.comC50
50www.twingate.comC50
51hetzner.comC40
52keepassxc.orgC40
53tails.netC40
54www.pfsense.orgC40
55www.wireguard.comC40
561984.hostingD35
57nordpass.comD30
58surfshark.comD30
59www.privateinternetaccess.comD30
60briarproject.orgD20
61contabo.comD20
62defined.netD20
63getoutline.orgD20
64hysteria.networkD20
65joplinapp.orgD20
66nginx.orgD20
67openvpn.netD20
68signal.orgD20
69simplex.chatD20
70tosdr.orgD20
71www.eff.orgD20
72www.netmaker.ioD20
73www.opnsense.orgD20
74www.ovhcloud.comD20
75www.portainer.ioD20
76www.strongswan.orgD20
77xtls.github.ioD20
78runbox.comF10
79www.cyberghostvpn.comF10
80www.digitalocean.comF10
81www.hostinger.comF10
82www.shadowsocks.orgF10
83zerotier.comF10
84caddyserver.comF0
85calyxos.orgF0
86delta.chatF0
87headscale.netF0
88husarnet.comF0
89keepass.infoF0
90pivpn.ioF0
91psono.comF0
92rclone.orgF0
93seafile.comF0
94syncthing.netF0
95uptimekuma.orgF0
96www.qubes-os.orgF0
97www.softether.orgF0
98www.tinc-vpn.orgF0
99www.veracrypt.frF0

Did your site earn an A+, A or B? Take the badge

If your site scored B or better, you are welcome to display it. The badge links back to this page so anyone can verify the grade against the published table and re-run the scanner themselves - which is the only reason a badge like this is worth anything.

There is one badge per grade. Swap -aplus for -a or -b to match the grade in the table above.

<a href="https://www.vpnsmith.com/en/blog/vpn-privacy-security-headers-2026">
  <img src="https://www.vpnsmith.com/badges/security-headers-2026-aplus.svg"
       alt="Security Headers 2026 - grade A+ - measured by VPNSmith" width="184" height="40">
</a>
gradebadge file
A+https://www.vpnsmith.com/badges/security-headers-2026-aplus.svg
Ahttps://www.vpnsmith.com/badges/security-headers-2026-a.svg
Bhttps://www.vpnsmith.com/badges/security-headers-2026-b.svg

Each badge is a static SVG with no script and no cookie. Being a privacy audience, you will want the rest of it stated plainly: served from our domain it is a third-party request, and our web server logs it the way any web server logs an image. So host it yourself - download the SVG, put it on your own domain, keep the link. That is the version we recommend, and it changes nothing for us: we count badges by reading public HTML, never by reading our logs.

No conditions attached. We do not ask for anything in return, we do not require the link to be followed, and the badge keeps working whether or not you tell us you used it.

Improved your headers? Ask for a re-test

The scanner is MIT-licensed and dependency-free, so you can reproduce our number before you even contact us. If you have changed your configuration and want the table to reflect it, say so and we will re-measure and update the row. A site raising its score is the outcome this page exists to encourage - a ranking that only names and shames is a ranking nobody improves for.

Reproduce every number here

The measurement is worth exactly as much as your ability to check it. The scanner queries each homepage once, reads the response headers, and applies the table above. No key, no scraping, no account.

The scanner: security-headers-scan.py — MIT, no dependencies, one argument (a text file with one domain per line). It queries each homepage once, reads the response headers, and applies the weights in the table above. Run it against this list and you should reproduce our column values exactly; if you do not, we would like to know.

If you want the wider context on why these headers matter for a self-hosted setup, our WireGuard vs OpenVPN comparison covers the transport side, and choosing a VPS for a VPN covers the host you would be hardening.

★ Nuremberg GDPR datacenter · ✓ Dedicated IPv4 included · 200+ Mbps guaranteed

Self-host your VPN on your own VPS → ContaboFull root access · public IPv4 · pick your region

Frequently asked questions

What exactly does this score measure?
The presence of eight HTTP security headers on the site's homepage, and nothing else. It is a measurement of what the web server declares to your browser - not a security audit of the product. A password manager can score F here and still have excellent cryptography, because the two things are unrelated. Read the grade as 'how much of the browser-side hardening is switched on', not as 'how safe is this tool'.
How is the score calculated?
Eight headers, weighted by what they actually prevent: Content-Security-Policy 25 points, Strict-Transport-Security 20, X-Content-Type-Options 10, X-Frame-Options 10, Referrer-Policy 10, Permissions-Policy 10, Cross-Origin-Opener-Policy 10, Cross-Origin-Resource-Policy 5. CSP and HSTS carry the most because they block whole classes of attack rather than one behaviour. A site using frame-ancestors inside its CSP gets the X-Frame-Options points, since that is the modern equivalent.
My site scores lower than I expected. Can I get it re-tested?
Yes. The scanner is published under the MIT licence and has no dependencies, so you can run it yourself and get the same number we did. If you change your headers and want the table updated, tell us and we will re-measure - a site improving its score is the outcome this ranking exists to encourage.
Why do some sites have no score at all?
Seven of the 106 sites we tried could not be measured: the request timed out, the certificate failed to validate from our vantage point, or the host refused an automated client. Those rows are left empty rather than scored zero. A failed measurement is not a finding, and treating it as one is how surveys quietly become wrong.
Does a high score mean the site is secure?
No, and it would be dishonest to imply otherwise. Security headers are one visible layer among many. A site can declare all eight and still have an application vulnerability, and a site can declare none and be perfectly well built underneath. What the headers do tell you is whether someone thought about browser-side defence in depth - which is a reasonable signal, and nothing more than a signal.