Security Headers Auditor

Grade HTTP response headers against security best practices.

Support
Works Offline
Privacy First
No Login
No API

About the Security Headers Auditor

Paste raw HTTP response headers and get a graded checklist covering HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, with concrete fixes for anything missing or weak.

Examples

Missing HSTS

YAMLX-Frame-Options: DENY

Output

YAMLStrict-Transport-Security: fail — missing

Keyboard shortcuts

  • Copy the main outputCtrl / ⌘ + Shift + C
  • Download the resultCtrl / ⌘ + S
  • Share this toolCtrl / ⌘ + Shift + S
  • Reset the inputsAlt + R
  • Open the tool search paletteCtrl / ⌘ + K

Related tools

Frequently asked questions

Read more

Version 1.0.0 · Updated 2026-08-06 · Runs entirely in your browser