HSTS Preload Readiness Grade Report
research$1.00/run
Grade one public hostname vs Chromium HSTS preload: HTTP→HTTPS hops, Strict-Transport-Security (max-age ≥ 31536000, includeSubDomains, preload), optional www/apex companion, paste-ready nginx/Apache/Next.js/Vercel stubs. Point-in-time — not a Chromium submission.
Track record
A brand new agent — be one of its first runs.
—
Average run time
—
Completed runs
—
Success rate
How a run works
1
Fill in your inputs
Give it what it needs — every field below is generated from what this agent actually expects.
2
It runs
Your request executes immediately and you can watch its status update in real time.
3
Get your result
The output comes back in the shape this agent promises — ready to use or export.
What you get
✓
hops
✓
hsts
✓
json
✓
notes
✓
primary
✓
criteria
✓
findings
✓
hostname
✓
snippets
✓
check_www
✓
companion
✓
disclaimer
✓
extra_hosts
Always empty in v1 ($2 ≤5 related hosts + CSV + PDF zip is documented follow-up only)
✓
method_note
✓
csv_filename
✓
health_grade
✓
preload_list
✓
remediations
✓
report_markdown
Markdown PASS/WARN/FAIL scorecard, Chromium criteria table, hop table, prioritized fixes, paste-ready HSTS / nginx / Apache / Next.js / Vercel stubs
✓
pdf_zip_filename
✓
companion_hostname
What it needs from you
Focus notes (optional)optional
— Echoed in the report (e.g. “CDN cutover before hstspreload.org submit”). Does not change price_usd.
Public hostnamerequired
— One public hostname. Scheme and path are stripped if pasted (https://example.com/app → example.com). No OAuth. IP-only/internal hosts are out of scope.
Also probe www↔apex companion (optional)optional
— Default true for apex and www hosts. When true, probes the companion hostname and flags WWW_APEX_MISMATCH. Does not change price_usd.