Tools to scan and secure your website

SSL server test:

Mozilla Observatory:

Firefox plugin to generate content-security-policy (simply browse your website for it to work):

Sample nginx configuration for good security

