nalyzed.

Security Headers Checker

Security headers tell browsers how strictly to treat a page. This check fetches the homepage and lists which protective headers are sent, with their raw values, so you can see what is missing and what to add.

Results open in the site's full report, which you can share, compare and re-run.

What it checks

  • Strict-Transport-Security (HSTS)
  • Content-Security-Policy, including frame-ancestors
  • X-Frame-Options and X-Content-Type-Options
  • Referrer-Policy and Permissions-Policy

Frequently asked questions

Does a present header mean the site is secure?
No. The report shows presence and the raw value. A CSP that allows everything is present but weak, so review the value itself.
Which header matters most?
HSTS and a Content-Security-Policy give the most protection: HSTS prevents HTTPS downgrades and CSP limits the damage of injected scripts.
Where do I add these headers?
In your web server, CDN or framework configuration, for example nginx add_header, Cloudflare Transform Rules or next.config headers().

More free tools

Türkçe