Mozilla Observatory is a free security headers audit tool maintained by Mozilla that grades any URL on HTTP security configuration. StoreVitals checks the same security headers as part of a continuous ecommerce health audit, with weekly monitoring and alerting on top.
Mozilla Observatory is the gold standard for a one-shot security headers audit — if you've never hardened your headers, run it once, fix what it flags, and you'll likely jump from D to A. StoreVitals catches the same misconfigurations but treats them as one of many ongoing ecommerce health signals. The right pattern: use Mozilla Observatory once during initial hardening, then use StoreVitals continuously to catch regressions when a deploy accidentally drops a header or someone changes the CDN. They're both free for a single URL — there's no reason not to use both.