Security

HTTP Security Headers Checker

Audit the HTTP security headers of any website. Score CSP, HSTS, X-Frame-Options, and more.

Domain or URL only — e.g. example.com or https://example.com/page → checks example.com

About this tool

What is HTTP Security Headers Checker?

Check any website's HTTP security headers. Get a pass/fail report for CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

http security headerssecurity headers checkercsp checkerhsts checkerx-frame-optionscontent security policy

FAQ

Frequently asked questions

What are HTTP security headers?

HTTP security headers are response headers that instruct browsers to enable built-in security controls, reducing risks like XSS, clickjacking, and MIME-type sniffing.

Which security header is most important?

Content-Security-Policy (CSP) and Strict-Transport-Security (HSTS) are generally considered the most impactful.

What is HSTS?

HTTP Strict Transport Security tells browsers to only connect to the site over HTTPS, even if the user types http://. This prevents SSL-stripping attacks.

What does X-Frame-Options do?

X-Frame-Options prevents your pages from being embedded in iframes on other domains, protecting against clickjacking attacks.

Related

automated security

Need continuous coverage?

PandaONE runs autonomous agents against your app, validates findings with proof, and opens fixes as pull requests.

Get started