LabPuff

Web

Security Header Checker

Inspect HSTS, CSP, frame protection and other browser security headers.

Public websites only. No signup. Results are not saved.

When to use this security header checker

Review browser security headers after a deployment or proxy change. This checker highlights whether common controls are present, without turning missing headers into a vulnerability score.

What to look for

  • Verify that HTTPS responses include the controls intended for your application.
  • Review CSP sources and frame restrictions against real features before changing policies.
  • Test changes in a staging environment; stricter policies can break scripts, embedding or integrations.

How to read the results

Missing headers are warnings, not proof of a vulnerability. Header values need review in the context of the site.

PASS marks a stated check that passed. WARNING deserves review. FAIL marks a failed check. INFORMATION reports a fact. Results are a snapshot from our server, not a score or certification.

Does a present Content Security Policy mean the site is secure?

No. A permissive or poorly matched policy may offer limited protection. Presence is an observation; evaluating effectiveness requires reviewing the policy and application behavior.

Download your results as Markdown to save the observations or discuss them with your AI assistant. Reports include the check timestamp and limitations.

CSP unsafe-inline: review the policy before removing it →