Security · response headers

Security headers analyzer.

Paste the raw response headers from your browser dev tools or curl -I. The page never requests your site; it only reads the text you paste.

OWASP Secure Headers data updated 13 September 2026 · MDN reviewed 30 September 2026Findings list, not a score

Advertisement

Paste response headers

Paste only headers you are authorized to inspect. Remove cookie values if you prefer; only attribute names are checked.

Findings

Your findings will appear here.

What this checks

Limits: This checks the header text you paste. It cannot see redirects, other pages, or what a browser actually enforces, and a clean result is not a security audit. HSTS is only honoured over HTTPS. Some OWASP recommendations (for example COEP require-corp or Cache-Control no-store) suit specific apps and are not flagged here.

Sources: OWASP Secure Headers Project · MDN HTTP headers · MDN HSTS · MDN Referrer-Policy · MDN Set-Cookie

Advertisement
Advertisement
Listening…