Free Tool

Security Headers Checker

Analyze your website's HTTP security headers. Check for HSTS, CSP, X-Frame-Options, and other security configurations.

Security Headers Explained

Strict-Transport-Security (HSTS)Forces HTTPS connections and prevents downgrade attacks
Content-Security-Policy (CSP)Prevents XSS and data injection attacks by controlling resource loading
X-Frame-OptionsPrevents clickjacking by controlling iframe embedding
X-Content-Type-OptionsPrevents MIME-type sniffing attacks
Referrer-PolicyControls how much referrer information is shared
Permissions-PolicyRestricts browser features like camera, microphone, geolocation