🛡️ Security Headers Checker

Enter a URL to review the security-related HTTP response headers it sends. Each header is classified as present, missing, or weak, with an explanation. The score is a transparent configuration assessment — not a certification.

Input

A bare domain is checked over HTTPS. Internal and private addresses are blocked.

Results

How It Works

The tool fetches the URL's response headers using this site's existing HTTP Headers checker, then evaluates nine security headers against common guidance — for example, a Content-Security-Policy containing unsafe-inline is reported as weak rather than simply present, and an HSTS max-age under six months is flagged as short.

Missing is not the same as vulnerable. Some headers are context-dependent (the Cross-Origin family matters most for sites using certain advanced browser APIs). Findings explain what each header does so you can decide what applies. The score gives each of the nine headers an equal share, counting weak headers as half — the breakdown is shown so you can see exactly where points came from. Only one Set-Cookie value is visible through the underlying headers checker.

Examples & Common Use Cases

  • Audit a site before launch for the common browser-enforced protections.
  • Verify that a CDN or reverse-proxy change didn't drop a header.
  • Spot a Server header that discloses detailed version information.