Enter the correct answer.
Today’s tool allowance
  • Domains: 3 left of 3
  • Unique URLs: 10 left of 10
  • Runs: 10 left of 10

Create a free account or see plans for higher limits.

Security headers and posture check

HTTP security headers reduce common browser attacks and signal operational maturity. This passive checker reviews HTTPS behavior and headers such as CSP, HSTS, X-Content-Type-Options, frame protections, and cookie flags—without attacking your site.

Headers worth prioritizing

  • HSTS on production HTTPS sites
  • Content-Security-Policy tailored to your real script sources
  • Secure, HttpOnly cookies for sessions
  • Clickjacking protections via CSP frame-ancestors or X-Frame-Options

How to remediate safely

Roll out CSP in report-only mode first, fix console violations, then enforce. Avoid copy-pasting overly strict policies that break payments or analytics. Re-scan after CDN or reverse-proxy changes.

Frequently asked questions

Is this a penetration test?

No. It is a passive configuration review of publicly visible responses.

Will better headers improve SEO directly?

Security headers are not classic ranking factors, but HTTPS and trustworthy sites support user trust and Core Web Vitals work.