Free interactive tool · 30 seconds
Are your security headers actually there?
Enter your website. We read the HTTP headers your server sends — HSTS, Content-Security-Policy, clickjacking protection — and score 10 of them. No email, nothing stored about the URL you check.
What it checks
The 10 headers that harden a site against the most common web attacks: HSTS (forced HTTPS), Content-Security-Policy (script allowlist), clickjacking protection, nosniff, referrer and permissions policies, version-disclosure, redirect hygiene, and charset. Scored out of 100 with a per-header breakdown.