Security · response headers
Security headers analyzer.
Paste the raw response headers from your browser dev tools or curl -I. The page never requests your site; it only reads the text you paste.
Paste response headers
Paste only headers you are authorized to inspect. Remove cookie values if you prefer; only attribute names are checked.
Findings
Your findings will appear here.
What this checks
- Content-Security-Policy: presence, unsafe-inline / unsafe-eval, wildcard sources, frame-ancestors
- Strict-Transport-Security: max-age (one year, 31536000 seconds, is the preload minimum) and includeSubDomains
- X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options
- Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy
- Set-Cookie: Secure, HttpOnly, SameSite and __Host- / __Secure- prefix rules
Limits: This checks the header text you paste. It cannot see redirects, other pages, or what a browser actually enforces, and a clean result is not a security audit. HSTS is only honoured over HTTPS. Some OWASP recommendations (for example COEP require-corp or Cache-Control no-store) suit specific apps and are not flagged here.
Sources: OWASP Secure Headers Project · MDN HTTP headers · MDN HSTS · MDN Referrer-Policy · MDN Set-Cookie