HTTP Headers Analyser
Paste a response's headers and see which protections are missing — the ones that never show up as an error.
Runs entirely in your browser
Loading tool...
How to use
- Run `curl -I https://your-site.com`, or copy the response headers from the network panel.
- Paste them here and read the security section first.
- Work down the findings — HSTS and CSP are the two with the most leverage.
- Re-check after deploying; header changes are easy to lose in a config merge.
Features
- Flags missing HSTS, CSP, frame protection, nosniff and Referrer-Policy.
- Recognises `frame-ancestors` as a replacement for X-Frame-Options.
- Notices an HSTS max-age too short to preload, and a policy that allows inline script.
- Points out a Server version and X-Powered-By, which help only an attacker.
- Runs entirely in your browser; nothing is fetched.
Frequently asked questions
- Which of these matters most?
- HSTS and CSP. HSTS closes the window where a visitor's first request can be downgraded to http and intercepted; CSP is the only thing standing between an injected script and your users' sessions. The rest are worth having and cheaper to add — nosniff and Referrer-Policy are one line each.
- Why flag a policy that has unsafe-inline?
- Because it permits exactly what the policy exists to stop. An injected `<script>` tag is inline script; a policy that allows inline script allows the injection. Use a nonce or a hash instead — that keeps your own inline scripts working and still blocks the attacker's.
- Why does the Server version matter?
- It does not create a hole, it tells an attacker which holes to try. `nginx/1.25.3` narrows a scan from every known vulnerability to the handful that affect that release. Turning the version off costs nothing and removes the shortcut.
Related tools
Finds the http:// references that break an HTTPS page, and separates the ones browsers block outright from the ones they quietly upgrade.
Read a Set-Cookie header attribute by attribute, and see which protections are missing.
Read the delivery path out of raw headers — who handed the message to whom, how long each hop took, and what the checks said.
Build a CSP directive by directive, with the two mistakes that make a policy useless flagged as you make them.