What does a security-headers checker inspect?
A security-headers checker fetches a public URL and reports whether the response includes browser protections for transport security, content execution, framing, MIME sniffing, referrer disclosure, and powerful features. The result helps find missing deployment configuration that application tests often overlook.
The checker follows the OWASP Secure Headers rule set and examines HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. Its percentage is an unweighted presence check: a weak or malformed header can still count as present, so values must be reviewed before treating the page as hardened.