Share
Audit response headers + get a security grade for any URL.
Inspect any website's HTTP response headers and get a security score. Checks for HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin headers and cookie flags. Surfaces missing or weak headers and explains what each does.
Share this tool
We make a GET request from our server (because most sites block cross-origin browser requests). Headers and cookies are returned as-is — your URL is never logged.