Security

HTTP Security Headers Checker

A security headers checker fetches a URL and reports which protective HTTP response headers are present, graded by severity. These headers are the cheapest security work available: each is a single server configuration line, and together they close off downgrade attacks, clickjacking, MIME sniffing and referrer leakage.

Last updated · Free, no signup

Loading interactive HTTP Security Headers Checker…

What does a security-headers checker inspect?

A security-headers checker fetches a public URL and reports whether the response includes browser protections for transport security, content execution, framing, MIME sniffing, referrer disclosure, and powerful features. The result helps find missing deployment configuration that application tests often overlook.

The checker follows the OWASP Secure Headers rule set and examines HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. Its percentage is an unweighted presence check: a weak or malformed header can still count as present, so values must be reviewed before treating the page as hardened.