Free Security Headers Checker

Test a site’s security headers, review missing protections, and get a clearer starting point for Content Security Policy (CSP) and header hardening work.

Use the free checker for point-in-time analysis, then move into hosted monitoring if you want alerts and header history.

Check Any Public Site

Run a quick check against public URLs to see what security headers are present, weak, or missing.

Understand the Grade

Review overall score, missing headers, and practical recommendations instead of reading raw responses by hand.

Move Into Monitoring

Use MetricPoints when you want to track changes over time and know when header configuration drifts in production.

Headers and Rules Checked

Content-Security-Policy

unsafe-inline, unsafe-eval, wildcards, HTTP sources, reporting, default-src, script-src, object-src, and base-uri

CSP Report-Only

Report-only policy posture when an enforcing CSP is absent or being tested

Strict-Transport-Security

max-age, includeSubDomains, and preload readiness

X-Frame-Options

DENY, SAMEORIGIN, deprecated ALLOW-FROM, and invalid values

X-Content-Type-Options

nosniff enforcement

Referrer-Policy

privacy strength across common referrer policies

Permissions-Policy

geolocation, microphone, camera, payment, USB, fullscreen, autoplay, picture-in-picture, and interest-cohort

X-XSS-Protection

legacy header review and modern CSP recommendation