Web
Security Header Checker
Inspect HSTS, CSP, frame protection and other browser security headers.
When to use this security header checker
Review browser security headers after a deployment or proxy change. This checker highlights whether common controls are present, without turning missing headers into a vulnerability score.
What to look for
- Verify that HTTPS responses include the controls intended for your application.
- Review CSP sources and frame restrictions against real features before changing policies.
- Test changes in a staging environment; stricter policies can break scripts, embedding or integrations.
How to read the results
Missing headers are warnings, not proof of a vulnerability. Header values need review in the context of the site.
PASS marks a stated check that passed. WARNING deserves review. FAIL marks a failed check. INFORMATION reports a fact. Results are a snapshot from our server, not a score or certification.
Does a present Content Security Policy mean the site is secure?
No. A permissive or poorly matched policy may offer limited protection. Presence is an observation; evaluating effectiveness requires reviewing the policy and application behavior.
Download your results as Markdown to save the observations or discuss them with your AI assistant. Reports include the check timestamp and limitations.