Free Security Headers Checker
Test a site’s security headers, review missing protections, and get a clearer starting point for Content Security Policy (CSP) and header hardening work.
Use the free checker for point-in-time analysis, then move into hosted monitoring if you want alerts and header history.
Check Any Public Site
Run a quick check against public URLs to see what security headers are present, weak, or missing.
Understand the Grade
Review overall score, missing headers, and practical recommendations instead of reading raw responses by hand.
Move Into Monitoring
Use MetricPoints when you want to track changes over time and know when header configuration drifts in production.
Headers and Rules Checked
Content-Security-Policy
unsafe-inline, unsafe-eval, wildcards, HTTP sources, reporting, default-src, script-src, object-src, and base-uri
CSP Report-Only
Report-only policy posture when an enforcing CSP is absent or being tested
Strict-Transport-Security
max-age, includeSubDomains, and preload readiness
X-Frame-Options
DENY, SAMEORIGIN, deprecated ALLOW-FROM, and invalid values
X-Content-Type-Options
nosniff enforcement
Referrer-Policy
privacy strength across common referrer policies
Permissions-Policy
geolocation, microphone, camera, payment, USB, fullscreen, autoplay, picture-in-picture, and interest-cohort
X-XSS-Protection
legacy header review and modern CSP recommendation