Security Headers Checker

Test CSP, HSTS, clickjacking, MIME sniffing, referrer privacy, browser permissions, and legacy XSS header posture in one pass.

🔒 Free Security Audit

Check any website instantly

Trusted by Teams That Care About Website Health

Join developers, agencies, and site owners who use MetricPoints to keep important websites watched after launch

200+
Websites Monitored
5,000+
Security Headers Checked
99.9%
Uptime Monitoring

Ready to Keep the Whole Website Watched?

Do not wait for the next audit to learn that something drifted. Monitor headers, CSP, DNS, domains, robots, sitemaps, forms, browser health, assets, backups, and other modern website-health signals with MetricPoints.

How Security Headers Work

Strict-Transport-Security (HSTS)

Forces browsers to use HTTPS connections, preventing man-in-the-middle attacks.

Content-Security-Policy (CSP)

Prevents XSS attacks by controlling which resources can be loaded and executed.

X-Frame-Options

Prevents clickjacking attacks by controlling if your site can be embedded in frames.

X-Content-Type-Options

Prevents browsers from MIME-sniffing files, reducing security risks.

Referrer-Policy

Controls how much referrer information is sent with requests.

Permissions-Policy

Controls which browser features and APIs can be used on your site.