Skip to main content
Free Tool · Security Header Checker

Grade your security headers in one shot.

Paste a URL and see which hardening headers you're missing — HSTS, CSP, X-Frame-Options and more — each with what it does and how to add it. No signup to try it.

Try
No signupUnlimited & free6 headers graded A–F

What the checker reads

01 / HSTS

Transport security.

Strict-Transport-Security forces HTTPS and closes the SSL-stripping downgrade window.

02 / CSP

Content-Security-Policy.

The single strongest defense against XSS — which scripts and resources may run.

03 / Framing

Clickjacking.

X-Frame-Options / frame-ancestors stop your page being embedded in a hostile iframe.

04 / Sniffing

MIME & referrer.

nosniff and Referrer-Policy stop content-type confusion and URL leakage.

05 / Disclosure

Fingerprinting.

Server and X-Powered-By version strings hand attackers a target list.

06 / Grade

A–F grade.

Weighted header coverage rolled into one letter grade and 0–100 score.