Security Headers Auditor

Grade HTTP response headers against security best practices.

Works Offline
Privacy First
No Login
No API

Response headers

Paste raw HTTP response headers (one per line).

Audit results

Analyzed locally — headers never leave your browser.

Paste response headers to see a graded security audit.

About the Security Headers Auditor

Paste raw HTTP response headers and get a graded checklist covering HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, with concrete fixes for anything missing or weak.

Examples

Missing HSTS

X-Frame-Options: DENY

Output

Strict-Transport-Security: fail — missing

Related tools

Frequently asked questions

Read more

Version 1.0.0 · Updated 2026-08-06 · Runs entirely in your browser