Check your website's HTTP security headers

Enter a public page URL to see which security headers its response sends. Check CSP, HSTS, frame protection and cookie flags, then review missing headers before changing your site.

–
headers
raw response headers
show raw headers

How do I check HTTP security headers?

Paste the URL of a public page you own or have permission to check, then select Scan. Open the raw response headers to see the values behind the score. You can also inspect a response in your browser's Network tab.

  1. Check the final URL and response status. A redirect may take you to a different page.
  2. Review each missing header and whether it makes sense for that page.
  3. Test any change on your own site, then scan the same URL again.

What do CSP and HSTS tell me?

Content-Security-Policy (CSP) limits which resources a page may load. Its settings matter: a header can exist and still allow too much. This checker mainly checks whether headers are present, not whether every policy is strong.

Strict-Transport-Security (HSTS) tells browsers to use HTTPS for future connections. Only enable it after checking your HTTPS setup. Adding includeSubDomains affects subdomains too, so don't copy a long-lived policy without testing.

Frame protection can use X-Frame-Options or CSP's frame-ancestors. Cookie checks apply only to cookies set on the response this tool receives.

Does an A+ mean my website is secure?

No. The score is this tool's weighted checklist across nine checks, not a security audit. It does not test login flows, application logic, all pages, or exploitable vulnerabilities. A missing header is a review item, not proof of a bug bounty finding.

The suggested lines are starting points, not ready-to-paste fixes for every site. A restrictive CSP can break scripts, styles or embeds. Review your site's needs and test first.

Example: review a missing CSP

If a result says CSP is missing, first list the scripts, styles and embeds your page needs. Test a policy in report-only mode before enforcing it. Recheck after deployment, and confirm the page still works. That is more useful than chasing a letter grade.

References and another free tool

MDN: Content-Security-Policy · MDN: HSTS · OWASP header guidance

Looking at JavaScript rather than response headers? Try JSRecon for static JavaScript review. Potential matches still need manual verification.