VibeCoden't

Security headers check

Check your website security headers online in seconds. Free, no signup, no credits used, we read one response from your site and tell you exactly which headers are missing and what to set instead.

Want the full picture?

Headers are just one of 20+ checks. Run a free vulnerability scan to catch exposed API keys, leaked configs, insecure cookies and more.

Run a free scan

What this checker looks at

Seven response headers do most of the work in a browser's defence: Content-Security-Policy stops injected scripts, Strict-Transport-Security keeps the connection encrypted, X-Content-Type-Options stops type guessing, Referrer-Policy keeps your URLs out of other people's logs, Permissions-Policy switches off camera and location access, Cross-Origin-Opener-Policy isolates your page from windows it opens, and X-Frame-Options blocks clickjacking. We also flag server banners that advertise an exact version number.

For the reasoning behind each value, read the security headers checklist. To see how headers feed into an overall grade, see website security score.