Security Headers Checker
Test CSP, HSTS, clickjacking, MIME sniffing, referrer privacy, browser permissions, and legacy XSS header posture in one pass.
🔒 Free Security Audit
Check any website instantly
Trusted by Teams That Care About Website Health
Join developers, agencies, and site owners who use MetricPoints to keep important websites watched after launch
Ready to Keep the Whole Website Watched?
Do not wait for the next audit to learn that something drifted. Monitor headers, CSP, DNS, domains, robots, sitemaps, forms, browser health, assets, backups, and other modern website-health signals with MetricPoints.
How Security Headers Work
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS connections, preventing man-in-the-middle attacks.
Content-Security-Policy (CSP)
Prevents XSS attacks by controlling which resources can be loaded and executed.
X-Frame-Options
Prevents clickjacking attacks by controlling if your site can be embedded in frames.
X-Content-Type-Options
Prevents browsers from MIME-sniffing files, reducing security risks.
Referrer-Policy
Controls how much referrer information is sent with requests.
Permissions-Policy
Controls which browser features and APIs can be used on your site.