Free Security Headers Checker
Review important security headers and configuration on a public page: HTTPS, redirects, HSTS, content types, framing, and cookie flags.
What is Security Headers?
A security headers checker inspects HTTP response headers and related page configuration that reduce common risks — without attacking or exploiting the site.
Why it matters
Missing headers leave avoidable gaps (downgrade attacks, clickjacking, script injection). Configuration checks catch the common ones quickly.
Common problems
- HSTS missing
- No Content-Security-Policy
- Cookies without Secure/HttpOnly
- Missing X-Content-Type-Options
- Mixed content on HTTPS pages
How to fix them
Add recommended headers at your server or CDN. Start with HSTS and frame protection if HTTPS is already on.
Example
Example: HTTPS on but HSTS missing → clients are not told to force HTTPS on future visits.
FAQ
Is this a penetration test?
No. Basic automated configuration checks only — not a penetration test or complete security audit.
Does it claim my site is secure?
Never. It lists what was and was not detected for public configuration.
Is it free?
Yes — free, no signup.
