Free interactive tool · 30 seconds

Are your security headers actually there?

Enter your website. We read the HTTP headers your server sends — HSTS, Content-Security-Policy, clickjacking protection — and score 10 of them. No email, nothing stored about the URL you check.

What it checks

The 10 headers that harden a site against the most common web attacks: HSTS (forced HTTPS), Content-Security-Policy (script allowlist), clickjacking protection, nosniff, referrer and permissions policies, version-disclosure, redirect hygiene, and charset. Scored out of 100 with a per-header breakdown.