Audit HTTP response security headers against best practices — HSTS, CSP, X-Frame-Options, X-Content-Type-Options and more. Paste raw headers from DevTools, or try a live fetch, and get an instant security grade with fix suggestions. No signup required.
Note: the browser may block cross-origin header reads. If that happens, use Option 2 below.
Custom APIs, dashboards, automations — whatever you need.
Start a Project →