🛡️ Security Headers Checker
Enter a URL to review the security-related HTTP response headers it sends. Each header is classified as present, missing, or weak, with an explanation. The score is a transparent configuration assessment — not a certification.
Input
Results
How It Works
The tool fetches the URL's response headers using this site's existing HTTP Headers checker, then evaluates nine security headers against common guidance — for example, a Content-Security-Policy containing unsafe-inline is reported as weak rather than simply present, and an HSTS max-age under six months is flagged as short.
Missing is not the same as vulnerable. Some headers are context-dependent (the Cross-Origin family matters most for sites using certain advanced browser APIs). Findings explain what each header does so you can decide what applies. The score gives each of the nine headers an equal share, counting weak headers as half — the breakdown is shown so you can see exactly where points came from. Only one Set-Cookie value is visible through the underlying headers checker.
Examples & Common Use Cases
- Audit a site before launch for the common browser-enforced protections.
- Verify that a CDN or reverse-proxy change didn't drop a header.
- Spot a Server header that discloses detailed version information.