Security header inspector
Spot missing or weak response-security headers and understand what each one does.
How it measures
- Headers are read from the final response after redirects.
- Findings are limited to presence and a few well-known weak patterns, each with an explanation.
Limits
- Headers alone do not establish that a site is secure, and missing headers do not prove it is vulnerable. This is a configuration review, not a vulnerability assessment.
- A CSP needs testing against your own pages; a strict policy can break legitimate functionality.
Troubleshooting
- CSP marked weak
- The policy allows unsafe-inline or wildcards. Move to nonces or hashes gradually, using report-only mode first.