Free Tool
Free Security Headers Checker
Check HTTPS, HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, cookie flags, and server header signals.
What this tool checks
Run one URL scan and get a complete report.
- HTTPS final URL
- HSTS
- Content-Security-Policy
- X-Frame-Options
- Referrer-Policy
- Permissions-Policy
- Cookie flags
How it works
The scanner fetches the public page, follows a limited redirect chain, collects headers/resources/HTML, applies self-owned detection rules, checks SEO/security/accessibility/performance signals, and returns evidence-backed fixes.
Private IPs, localhost, file URLs, and internal hostnames are blocked to reduce SSRF and abuse risk.
Related tools