🔐 Security Headers Checker

Analyze HTTP security headers on any website to identify missing security configurations and improve your web application's security posture. Check for essential headers like CSP, X-Frame-Options, HSTS, and more.

💡 Tip: Enter a complete URL (including https://) and click "Check Security Headers" to analyze the website's security configuration.
Enter a website URL and click "Check Security Headers" to view results.

Present is not the same as strong

Our server requests the URL you type and lists the security headers that came back, each marked present, with a count at the top. It is a real response from the live site - but it reports what is there, not how good it is. Both of these count as one header found:

Strict-Transport-Security: max-age=300
Content-Security-Policy: default-src *; script-src * 'unsafe-inline'

The first expires after five minutes and the second permits any script from anywhere, inline included. Reading the values is the part that has to be done by eye.

What to look for in each value

HeaderThe weak version
Strict-Transport-Securitymax-age well under 31536000, or no includeSubDomains
Content-Security-Policy'unsafe-inline' or a bare * in script-src; no frame-ancestors
X-Content-Type-Optionsanything but nosniff - the header has one valid value
Referrer-Policyunsafe-url, or no-referrer-when-downgrade, both looser than the browser default
Cookies are worth checking at the same time, in your browser's network tab. A session cookie wants Secure, HttpOnly and a SameSite value; omit SameSite and Chrome treats it as Lax, while other browsers may not.

Frequently asked questions

Can I check a page behind a login?

No. The request leaves our server with no cookies of yours, so you get the public response. For an authenticated route, use your browser's network tab or curl -I with your own session.

My homepage passes - does the whole site?

Not necessarily. Headers are set per server block, per location or per route, and it is common for an API path, a static-file directory or an error page to miss the set that the homepage has. Check a few real URLs.

Which headers are actually worth adding?

Four carry most of the weight: Strict-Transport-Security with a one-year max-age, X-Content-Type-Options: nosniff, a Content-Security-Policy that at minimum sets frame-ancestors, and Referrer-Policy. The rest are refinements or, like X-XSS-Protection, obsolete.