Are your security headers in place?

Verify CSP, HSTS, X-Frame-Options, Referrer-Policy and other HTTP security headers in one scan

Live HTTP probe — server response only No account required
Headers checked Content-Security-Policy HSTS X-Frame-Options Referrer-Policy Permissions-Policy

Why security headers matter

Modern browsers rely on response headers to enforce XSS, clickjacking and HTTPS policies. Missing headers let avoidable attacks through.

What gets checked?

Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy — with status per header.

Read more →

Quick wins

A handful of one-line config changes typically lifts a site from F to A. We highlight the cheapest improvements first.

Read the docs →