HTTP Header Security Analyser
Paste raw HTTP response headers to get a full security audit — grade, per-check badges, and actionable recommendations. Checks HSTS, CSP, clickjacking protection, MIME sniffing, referrer policy, information leakage, CORS, caching, cookie flags, and more. Nothing leaves your browser.
Collect headers with:
curl -sI https://example.com
— or —
Browser DevTools → Network → any request → Response Headers tab