Security Headers Auditor

Grade HTTP response headers against security best practices.

Support
Works Offline
Privacy First
No Login
No API

Response headers

Paste raw HTTP response headers (one per line).

Audit results

Analyzed locally — headers never leave your browser.

Paste response headers to see a graded security audit.

About the Security Headers Auditor

Paste raw HTTP response headers and get a graded checklist covering HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, with concrete fixes for anything missing or weak.

Examples

Missing HSTS

X-Frame-Options: DENY

Output

Strict-Transport-Security: fail — missing

Keyboard shortcuts

  • Copy the main outputCtrl / ⌘ + Shift + C
  • Download the resultCtrl / ⌘ + S
  • Share this toolCtrl / ⌘ + Shift + S
  • Reset the inputsAlt + R
  • Open the tool search paletteCtrl / ⌘ + K

Related tools

Frequently asked questions

Read more

Comments

No login needed. Comments appear after a quick review.

Protected by an on-site captcha — no third-party trackers.

Optional: get an alert when your comment is published or replied to, plus new tool announcements. No sign-up.

Loading comments…

Version 1.0.0 · Updated 2026-08-06 · Runs entirely in your browser