Free Tool · Security Header Checker
Grade your security headers in one shot.
Paste a URL and see which hardening headers you're missing — HSTS, CSP, X-Frame-Options and more — each with what it does and how to add it. No signup to try it.
Try
No signupUnlimited & free6 headers graded A–F
What the checker reads
01 / HSTS
Transport security.
Strict-Transport-Security forces HTTPS and closes the SSL-stripping downgrade window.
02 / CSP
Content-Security-Policy.
The single strongest defense against XSS — which scripts and resources may run.
03 / Framing
Clickjacking.
X-Frame-Options / frame-ancestors stop your page being embedded in a hostile iframe.
04 / Sniffing
MIME & referrer.
nosniff and Referrer-Policy stop content-type confusion and URL leakage.
05 / Disclosure
Fingerprinting.
Server and X-Powered-By version strings hand attackers a target list.
06 / Grade
A–F grade.
Weighted header coverage rolled into one letter grade and 0–100 score.