← All tools
CyberWorldOps / tools

Security Headers Checker

Inspect the security headers returned by a public website and find configuration improvements.

01

Website URL

Runs a limited check of public data. Inputs and results are not saved to a database.

How it works

Reads the headers of one public HTTP response, following up to three redirects. The six checks cover CSP, HSTS, MIME sniffing, framing, referrer disclosure and browser permissions. Header coverage is an observation, not a certification or a vulnerability scan.

Results may differ by URL, CDN, status code, user agent or geography. A block page is not your application response. Examples are starting points: adapt and test them against your application before deployment. The submitted URL is requested from our server; private addresses and custom ports are excluded.

Sources & standards

OWASP Secure Headers ↗