Skip to content

Security header inspector

Spot missing or weak response-security headers and understand what each one does.

Anonymous checks are limited to 10 per minute and 60 per hour per address. Results are cached for 60 seconds and not published anywhere.

How it measures

  • Headers are read from the final response after redirects.
  • Findings are limited to presence and a few well-known weak patterns, each with an explanation.

Limits

  • Headers alone do not establish that a site is secure, and missing headers do not prove it is vulnerable. This is a configuration review, not a vulnerability assessment.
  • A CSP needs testing against your own pages; a strict policy can break legitimate functionality.

Troubleshooting

CSP marked weak
The policy allows unsafe-inline or wildcards. Move to nonces or hashes gradually, using report-only mode first.

Related tools