🔐 Security Headers Checker
Analyze HTTP security headers on any website to identify missing security configurations and improve your web application's security posture. Check for essential headers like CSP, X-Frame-Options, HSTS, and more.
Present is not the same as strong
Our server requests the URL you type and lists the security headers that came back, each marked present, with a count at the top. It is a real response from the live site - but it reports what is there, not how good it is. Both of these count as one header found:
Strict-Transport-Security: max-age=300
Content-Security-Policy: default-src *; script-src * 'unsafe-inline'
The first expires after five minutes and the second permits any script from anywhere, inline included. Reading the values is the part that has to be done by eye.
What to look for in each value
| Header | The weak version |
|---|---|
| Strict-Transport-Security | max-age well under 31536000, or no includeSubDomains |
| Content-Security-Policy | 'unsafe-inline' or a bare * in script-src; no frame-ancestors |
| X-Content-Type-Options | anything but nosniff - the header has one valid value |
| Referrer-Policy | unsafe-url, or no-referrer-when-downgrade, both looser than the browser default |
Secure,
HttpOnly and a SameSite value; omit SameSite and
Chrome treats it as Lax, while other browsers may not.Frequently asked questions
Can I check a page behind a login?
No. The request leaves our server with no cookies of yours, so you get the
public response. For an authenticated route, use your browser's network tab or
curl -I with your own session.
My homepage passes - does the whole site?
Not necessarily. Headers are set per server block, per location or per route, and it is common for an API path, a static-file directory or an error page to miss the set that the homepage has. Check a few real URLs.
Which headers are actually worth adding?
Four carry most of the weight: Strict-Transport-Security with a one-year max-age, X-Content-Type-Options: nosniff, a Content-Security-Policy that at minimum sets frame-ancestors, and Referrer-Policy. The rest are refinements or, like X-XSS-Protection, obsolete.