Security Headers Analyzer

Analyze HTTP security headers to identify vulnerabilities and improve web security

Enter URL to Analyze

About Security Headers

Critical Headers

  • Strict-Transport-Security (HSTS): Forces HTTPS connections
  • Content-Security-Policy (CSP): Prevents XSS and injection attacks
  • X-Frame-Options: Protects against clickjacking
  • X-Content-Type-Options: Prevents MIME-type sniffing

Recommended Headers

  • Referrer-Policy: Controls referrer information
  • Permissions-Policy: Controls browser features
  • Cross-Origin headers: Isolates browsing contexts