# mozilla/http-observatory

Mozilla HTTP Observatory

Repository: https://github.com/mozilla/http-observatory
Canonical: https://ross.abutalabs.com/products/http-observatory
Homepage: https://observatory.mozilla.org/
Language: Python
License: MPL-2.0
License Family: copyleft
Archived: true
Last push: 2024-10-22T09:18:12+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3864, "days_push": 680, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1850, forks 164 (observed 2026-08-28T04:05:44.277994+00:00)

## What it is
Mozilla HTTP Observatory is a Python-based scanner and grader that analyzes websites' HTTP headers and security configurations, providing actionable feedback on security best practices. This repository is deprecated in favor of the MDN-maintained Node.js replacement (mdn/mdn-http-observatory).

## Use cases
- scan my website for http header security issues
- grade my site's security headers
- check if my site uses CSP, HSTS and other security headers
- run a security header scan in CI
- self-host a website security scanner
- audit http security configuration of a domain

## When to choose
- you need the original Python implementation for legacy integrations
- you want to self-host the classic Observatory scanner/grader

## When to avoid
- starting a new project - use the MDN mdn-http-observatory replacement instead
- you need updated scoring or bug fixes
- you want official support

## Facets
- artifact type: service
- maturity: abandoned
- function: security, vulnerability-scanning, http-server, monitoring
- domain: security, web-development, developer-tools
- platform: python, self-hosted, cli
- tags: http-headers, website-security-scanner, deprecated, observatory, security-grading, ci-integration, web-server

## Member repositories
- mozilla/http-observatory (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:44.277994+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:17:08.130455+00:00, confidence not recorded.
  - readme: https://github.com/mozilla/http-observatory (fetched 2026-08-28T04:05:44.277994+00:00, sha abd21ba7ef24)
  - homepage: https://observatory.mozilla.org/ (fetched 2026-08-29T10:56:38.386539+00:00, sha bc2bb7e4aed6)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML (fetched 2026-08-29T10:56:38.395638+00:00, sha 66bf4a25f44a)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements (fetched 2026-08-29T10:56:38.397837+00:00, sha a6c21ef2f053)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Global_attributes (fetched 2026-08-29T10:56:38.400320+00:00, sha e2025dfddb5b)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Attributes (fetched 2026-08-29T10:56:38.402181+00:00, sha dc19bdcf5efd)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference (fetched 2026-08-29T10:56:38.404208+00:00, sha e154bd54ce2b)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Guides/Responsive_images (fetched 2026-08-29T10:56:38.405797+00:00, sha 8807d18c08e4)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Guides/Cheatsheet (fetched 2026-08-29T10:56:38.407853+00:00, sha 797cb95cf18e)
  - site_page: https://developer.mozilla.org/en-US/docs/Web/HTML/Guides/Date_and_time_formats (fetched 2026-08-29T10:56:38.409675+00:00, sha f9a25082e203)
- Data as of 2026-08-30T08:39:29.467469+00:00.
