Security Tools

Security Header Analyzer

Grade the security headers of any page. Enter a URL and our server fetches its response headers, or paste headers from your browser’s developer tools to analyse them locally. The analyzer checks Strict-Transport-Security (age, subdomains, preload), Content-Security-Policy (with a CSP score), X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy, and warns when Server or X-Powered-By headers reveal software versions.

  • Encrypted connection
  • No sign-up
  • Free to use

A URL is fetched once by our server (public addresses only); pasted headers are analysed in your browser and never sent.

How to use Security Header Analyzer

  1. Enter a URL or paste response headers.
  2. Click Analyze headers.
  3. Fix the red items first.
  4. Run the check again after deploying.

Security Header Analyzer features

Grade and score

Weighted towards HSTS and CSP.

Paste mode

For staging or internal sites.

Version leaks

Server, X-Powered-By, X-AspNet-Version.

All headers

Full list for reference.

Explained findings

What and why.

Deprecated headers

X-XSS-Protection advice.

When to use Security Header Analyzer

  • Release checklists.
  • Penetration test preparation.
  • Hosting migrations.
  • Comparing CDN configurations.

Security Header Analyzer FAQ

Which headers matter most?

HSTS and a strict Content-Security-Policy give the biggest protection, followed by X-Content-Type-Options and frame-ancestors.

Is X-XSS-Protection still needed?

No – it is deprecated. Send 0 or omit it and rely on CSP.

Why hide Server versions?

Version numbers help attackers find known vulnerabilities quickly.

How do I add these headers?

In your web server, CDN or application. The security headers generator writes the configuration.

Defence in depth

Security headers do not fix vulnerabilities in your code, but they limit what an attacker can do with one – for example, a strict CSP stops most injected scripts from running.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools