Enter a public page URL to see which security headers its response sends. Check CSP, HSTS, frame protection and cookie flags, then review missing headers before changing your site.
Paste the URL of a public page you own or have permission to check, then select Scan. Open the raw response headers to see the values behind the score. You can also inspect a response in your browser's Network tab.
Content-Security-Policy (CSP) limits which resources a page may load. Its settings matter: a header can exist and still allow too much. This checker mainly checks whether headers are present, not whether every policy is strong.
Strict-Transport-Security (HSTS) tells browsers to use HTTPS for future connections. Only enable it after checking your HTTPS setup. Adding includeSubDomains affects subdomains too, so don't copy a long-lived policy without testing.
Frame protection can use X-Frame-Options or CSP's frame-ancestors. Cookie checks apply only to cookies set on the response this tool receives.
No. The score is this tool's weighted checklist across nine checks, not a security audit. It does not test login flows, application logic, all pages, or exploitable vulnerabilities. A missing header is a review item, not proof of a bug bounty finding.
The suggested lines are starting points, not ready-to-paste fixes for every site. A restrictive CSP can break scripts, styles or embeds. Review your site's needs and test first.
If a result says CSP is missing, first list the scripts, styles and embeds your page needs. Test a policy in report-only mode before enforcing it. Recheck after deployment, and confirm the page still works. That is more useful than chasing a letter grade.
MDN: Content-Security-Policy · MDN: HSTS · OWASP header guidance
Looking at JavaScript rather than response headers? Try JSRecon for static JavaScript review. Potential matches still need manual verification.