HTTPS and transport security
Strict-Transport-Security helps browsers use encrypted HTTPS connections instead of falling back to insecure HTTP.
Check the HTTP security headers of any public website. Find missing protections, risky configuration and information leaks, then get practical remediation guidance — no account required.
HTTP security headers tell browsers how to handle your website and which potentially dangerous behaviors to restrict. A missing or weak header can leave users more exposed to attacks such as clickjacking, content injection or insecure transport.
The scanner requests the public URL you provide, reads its HTTP response headers and evaluates the detected security controls. The resulting report highlights missing protections, risky values and information that may unnecessarily reveal details about the server.
Need the complete response instead of a security score?View all HTTP response headers.
The scan covers the following HTTP security headers. Some are recommended broadly, while others only apply to particular applications or response types.
Strict-Transport-Security helps browsers use encrypted HTTPS connections instead of falling back to insecure HTTP.
These headers restrict which resources can run, how the page may be embedded, what browser features it can use, and how referrer information is shared.
Cross-origin policies control how the document interacts with resources and browsing contexts served by other origins.
These situational headers can clear local browser data or restrict behavior retained for compatibility with older clients and plugins.
Provide the HTTPS or HTTP address you want to inspect.
The scanner retrieves the response and analyzes the supported headers and their values.
See which protections passed, which require attention and how the configuration can be improved.
The report separates correctly detected protections from headers that are missing, weak or require review. It may also identify response headers that reveal unnecessary information about the server or application.
A strong result means that the analyzed response has a solid browser-facing security configuration. It does not prove that the website is free from vulnerabilities. Security headers are one layer of defence and must be combined with secure application code, access control, dependency management and regular security testing.
This is a focused HTTP security header scanner, not a complete website vulnerability scanner or penetration test. It does not authenticate to your application, crawl every route, test business logic, exploit vulnerabilities or inspect server-side source code.
Results apply to the public response returned for the scanned URL. Other pages, APIs and authenticated areas may return different headers and should be tested separately.
HTTP security headers are response headers that instruct a browser to enforce protections such as HTTPS, content restrictions, framing controls and cross-origin isolation.
Enter a public URL into the scanner. It retrieves the HTTP response, identifies supported security headers and evaluates the values it receives.
The appropriate configuration depends on the application, but commonly relevant headers include Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
No. It indicates that the analyzed response has stronger browser-facing controls. It does not test application logic, authentication, dependencies or server-side vulnerabilities.
No. They can reduce the likelihood or impact of several browser-based attacks, but they are a defence-in-depth measure rather than a replacement for secure development and security testing.
| URL | Date | Score |
|---|---|---|