Most header questions are not security questions
Why is the CDN still serving the old version. Why does this file download instead of displaying. Why is the page not being cached. Why did this request end up on a different URL. Why is compression not being applied. Every one of those is answered by a response header, and none of them appears on a security scorecard.
Seeing the whole set at once is what makes those diagnosable. Cache-control against the age header tells you whether an edge cache is holding a stale copy and for how long. Content-type explains a file that downloads rather than renders, and content-disposition explains the rest. A grade cannot tell you any of that, because it was never trying to.
The security headers worth having, briefly
Strict-Transport-Security, so a browser refuses to speak plain HTTP to your domain after the first visit. X-Content-Type-Options set to nosniff, so a browser does not second-guess your content type and execute something as script that you served as text. A sensible Referrer-Policy, so full URLs including their query strings are not leaked to every third party you link to. X-Frame-Options or a frame-ancestors directive, so your pages cannot be embedded invisibly in somebody else.
Content-Security-Policy is the one that matters most and the one nobody ships, because it takes real work to write and breaks the site while you get it wrong. A missing CSP is not an emergency on a page with no user input and no third-party scripts. On anything handling sessions or accepting content, it is the difference between an injected script being an incident and being a non-event.
Headers are public, which cuts both ways
Every response header is sent to anyone who requests the URL, so checking them for a site you do not own is neither an attack nor a grey area - it is reading what the server volunteers to every visitor. That makes header inspection a legitimate part of evaluating a vendor, debugging an integration, or working out how a competitor has configured their caching.
It also means your own headers are public. Version numbers in a server header, an internal hostname in a redirect, a framework name and version - all of it is readable by anyone, and all of it narrows an attacker search for a known vulnerability. Removing what you do not need to advertise is the cheapest hardening there is.