Skip to content
Toolbench

HTTP Headers Analyser

Paste a response's headers and see which protections are missing — the ones that never show up as an error.

Runs entirely in your browser

Loading tool...

How to use

  1. Run `curl -I https://your-site.com`, or copy the response headers from the network panel.
  2. Paste them here and read the security section first.
  3. Work down the findings — HSTS and CSP are the two with the most leverage.
  4. Re-check after deploying; header changes are easy to lose in a config merge.

Features

  • Flags missing HSTS, CSP, frame protection, nosniff and Referrer-Policy.
  • Recognises `frame-ancestors` as a replacement for X-Frame-Options.
  • Notices an HSTS max-age too short to preload, and a policy that allows inline script.
  • Points out a Server version and X-Powered-By, which help only an attacker.
  • Runs entirely in your browser; nothing is fetched.

Frequently asked questions

Which of these matters most?
HSTS and CSP. HSTS closes the window where a visitor's first request can be downgraded to http and intercepted; CSP is the only thing standing between an injected script and your users' sessions. The rest are worth having and cheaper to add — nosniff and Referrer-Policy are one line each.
Why flag a policy that has unsafe-inline?
Because it permits exactly what the policy exists to stop. An injected `<script>` tag is inline script; a policy that allows inline script allows the injection. Use a nonce or a hash instead — that keeps your own inline scripts working and still blocks the attacker's.
Why does the Server version matter?
It does not create a hole, it tells an attacker which holes to try. `nginx/1.25.3` narrows a scan from every known vulnerability to the handful that affect that release. Turning the version off costs nothing and removes the shortcut.

Finds the http:// references that break an HTTPS page, and separates the ones browsers block outright from the ones they quietly upgrade.

Read a Set-Cookie header attribute by attribute, and see which protections are missing.

Read the delivery path out of raw headers — who handed the message to whom, how long each hop took, and what the checks said.

Build a CSP directive by directive, with the two mistakes that make a policy useless flagged as you make them.